CVE-2026-102261
owen2345 Camaleon CMS Media Crop media_controller.rb crop authorization
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th
A flaw has been found in owen2345 Camaleon CMS up to 2.9.2. Impacted is the function crop of the file app/controllers/camaleon_cms/admin/media_controller.rb of the component Media Crop Handler. This manipulation of the argument saved_avatar causes authorization bypass. The attack may be initiated remotely. The exploit has been published and may be used. Upgrading to version 2.9.3 is recommended to address this issue. Patch name: c143e145caa600947e70a240e87f2fed889149d3. It is suggested to upgrade the affected component.
| CWE | CWE-639 CWE-285 |
| Vendor | owen2345 |
| Product | camaleon cms |
| Published | Sep 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for owen2345 camaleon cms
Be the first to know when new medium vulnerabilities affecting owen2345 camaleon cms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
owen2345 / Camaleon CMS
2.9.0 2.9.1 2.9.2
References
vuldb.com: https://vuldb.com/vuln/411164 vuldb.com: https://vuldb.com/vuln/411164/cti vuldb.com: https://vuldb.com/cve/CVE-2026-102261 vuldb.com: https://vuldb.com/submit/934944 github.com: https://github.com/owen2345/camaleon-cms/commit/c143e145caa600947e70a240e87f2fed889149d3 github.com: https://github.com/owen2345/camaleon-cms/releases/tag/2.9.3
Credits
๐ 7acini (VulDB User) VulDB Vulnerability Moderation Team