Owen2345 · Camaleon Cms · CVE-2026-102261
**Name of the Vulnerable Software and Affected Versions**
owen2345 Camaleon CMS versions prior to 2.9.3
**Description**
A flaw in the Media Crop Handler component allows for a remote authorization bypass. The issue exists within the `crop()` function located in the `app/controllers/camaleon cms/admin/media controller.rb` file, where manipulation of the `saved avatar` argument enables the bypass.
**Recommendations**
Upgrade to version 2.9.3.