Authorization Bypass in Camaleon CMS Affects User Permissions
CVE-2026-67616

5.3MEDIUM

Key Information:

Vendor

Owen2345

Vendor
CVE Published:
3 August 2026

What is CVE-2026-67616?

Camaleon CMS versions up to 2.9.2 are impacted by a missing authorization vulnerability on the drafts endpoint. This flaw enables any authenticated low-privileged user to bypass role and permission checks, allowing for the unauthorized creation of draft posts. Attackers can exploit this vulnerability by sending requests to the drafts endpoint, leveraging only session authentication. As a result, unauthorized drafts may appear in the administrative drafts queue, potentially posing significant security risks within the content management system.

Affected Version(s)

camaleon-cms 0 <= 2.9.2

camaleon-cms 0 <= 2.9.2

camaleon-cms 88ab703b5ac041afb93a9993470aa366093c5311

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Amir Aliu
Enrik Mustafa
.