Missing Authorization Vulnerability in CamaleonCMS Plugins by Camaleon
CVE-2026-73326

7.2HIGH

Key Information:

Vendor

Owen2345

Vendor
CVE Published:
12 August 2026

What is CVE-2026-73326?

CamaleonCMS has a vulnerability that allows authenticated users with low privileges to access and alter plugin settings. This issue arises due to missing authorization checks on four unprotected plugin-administration endpoints. Attackers can exploit this weakness to manipulate configuration parameters across various plugins, including 'front_cache', 'cama_meta_tag', and 'cama_contact_form'. Consequently, this could lead to altered cached page behavior or manipulation of public output, including meta-tags and contact forms. When combined with stored cross-site scripting vulnerabilities, there is a heightened risk of account takeover, making it essential for users of CamaleonCMS to apply the latest security patches.

Affected Version(s)

CamaleonCMS 0 <= 2.9.1

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Amir Aliu & Enrik Mustafa
.