Authorization Bypass in Camaleon CMS Affects User Permissions
CVE-2026-67616
5.3MEDIUM
What is CVE-2026-67616?
Camaleon CMS versions up to 2.9.2 are impacted by a missing authorization vulnerability on the drafts endpoint. This flaw enables any authenticated low-privileged user to bypass role and permission checks, allowing for the unauthorized creation of draft posts. Attackers can exploit this vulnerability by sending requests to the drafts endpoint, leveraging only session authentication. As a result, unauthorized drafts may appear in the administrative drafts queue, potentially posing significant security risks within the content management system.
Affected Version(s)
camaleon-cms 0 <= 2.9.2
camaleon-cms 0 <= 2.9.2
camaleon-cms 88ab703b5ac041afb93a9993470aa366093c5311
