Unknown · Camaleon Cms · CVE-2026-67616
**Name of the Vulnerable Software and Affected Versions**
Camaleon CMS versions prior to 2.9.3
**Description**
A missing authorization issue exists on the 'drafts' endpoint. This allows an authenticated user with low privileges to bypass role and permission checks and create draft posts. By using only session authentication, an attacker can send requests to the 'drafts' endpoint to create unauthorized drafts that then appear in the administrative drafts queue.
**Recommendations**
Update Camaleon CMS to version 2.9.3 or later.
As a temporary mitigation, restrict access to the 'drafts' endpoint for low-privileged users.