๐Ÿ” CVE Alert

CVE-2026-102261

MEDIUM 5.4

owen2345 Camaleon CMS Media Crop media_controller.rb crop authorization

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

A flaw has been found in owen2345 Camaleon CMS up to 2.9.2. Impacted is the function crop of the file app/controllers/camaleon_cms/admin/media_controller.rb of the component Media Crop Handler. This manipulation of the argument saved_avatar causes authorization bypass. The attack may be initiated remotely. The exploit has been published and may be used. Upgrading to version 2.9.3 is recommended to address this issue. Patch name: c143e145caa600947e70a240e87f2fed889149d3. It is suggested to upgrade the affected component.

CWE CWE-639 CWE-285
Vendor owen2345
Product camaleon cms
Published Sep 29, 2026
Stay Ahead of the Next One

Get instant alerts for owen2345 camaleon cms

Be the first to know when new medium vulnerabilities affecting owen2345 camaleon cms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

owen2345 / Camaleon CMS
2.9.0 2.9.1 2.9.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/411164 vuldb.com: https://vuldb.com/vuln/411164/cti vuldb.com: https://vuldb.com/cve/CVE-2026-102261 vuldb.com: https://vuldb.com/submit/934944 github.com: https://github.com/owen2345/camaleon-cms/commit/c143e145caa600947e70a240e87f2fed889149d3 github.com: https://github.com/owen2345/camaleon-cms/releases/tag/2.9.3

Credits

๐Ÿ” 7acini (VulDB User) VulDB Vulnerability Moderation Team