PT-2026-71258 · Unknown · Camaleon Cms

CVE-2026-73326

·

Published

2026-08-12

·

Updated

2026-08-12

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions CamaleonCMS (affected versions not specified)
Description Missing authorization allows authenticated low-privileged users to access and modify plugin settings via four unprotected plugin-administration endpoints. This allows the manipulation of configuration parameters at runtime for the front cache, cama meta tag, and cama contact form plugins. Such actions can alter cached page behavior, modify public meta-tag output, or reconfigure contact forms. When combined with stored cross-site scripting (XSS)—a technique where malicious scripts are permanently stored on the target server—via the before html field of the contact form, this can lead to account takeover.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73326

Affected Products

Camaleon Cms