PT-2026-102448 · Owen2345 · Camaleon Cms

·

CVE-2026-102261

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions owen2345 Camaleon CMS versions prior to 2.9.3
Description A flaw in the Media Crop Handler component allows for a remote authorization bypass. The issue exists within the crop() function located in the app/controllers/camaleon cms/admin/media controller.rb file, where manipulation of the saved avatar argument enables the bypass.
Recommendations Upgrade to version 2.9.3.

Exploit

Fix

IDOR

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102261

Affected Products

Camaleon Cms