CVE-2026-67616
MEDIUMCamaleon CMS 2.9.2 Missing Authorization via /admin/post_type drafts endpoint
Title source: cnaDescription
Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoint that allows any authenticated low-privileged user to create draft posts by bypassing role and permission checks. Attackers can send requests to the drafts endpoint using only session authentication to create unauthorized drafts that appear in the administrative drafts queue.
References (3)
Core 3
Core References
Patch patch
Patch Commit
https://github.com/owen2345/camaleon-cms/commit/88ab703b5ac041afb93a9993470aa366093c5311
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/camaleon-cms-missing-authorization-via-admin-post-type-drafts-endpoint
Scores
CVSS v3
4.3
EPSS
0.0025
EPSS Percentile
16.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-862
Status
published
Products (2)
owen2345/camaleon-cms
< 2.9.2
owen2345/camaleon-cms
88ab703b5ac041afb93a9993470aa366093c5311
Published
Aug 03, 2026
Tracked Since
Aug 04, 2026