CVE-2026-67616

MEDIUM

Camaleon CMS 2.9.2 Missing Authorization via /admin/post_type drafts endpoint

Title source: cna
STIX 2.1

Description

Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoint that allows any authenticated low-privileged user to create draft posts by bypassing role and permission checks. Attackers can send requests to the drafts endpoint using only session authentication to create unauthorized drafts that appear in the administrative drafts queue.

Scores

CVSS v3 4.3
EPSS 0.0025
EPSS Percentile 16.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (2)
owen2345/camaleon-cms < 2.9.2
owen2345/camaleon-cms 88ab703b5ac041afb93a9993470aa366093c5311
Published Aug 03, 2026
Tracked Since Aug 04, 2026