PT-2026-67534 · Unknown · Camaleon Cms

·

CVE-2026-67616

·

Published

2026-08-03

·

Updated

2026-08-31

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Camaleon CMS versions prior to 2.9.3
Description A missing authorization issue exists on the 'drafts' endpoint. This allows an authenticated user with low privileges to bypass role and permission checks and create draft posts. By using only session authentication, an attacker can send requests to the 'drafts' endpoint to create unauthorized drafts that then appear in the administrative drafts queue.
Recommendations Update Camaleon CMS to version 2.9.3 or later. As a temporary mitigation, restrict access to the 'drafts' endpoint for low-privileged users.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67616

Affected Products

Camaleon Cms