CVE-2026-56720
CamaleonCMS 2.9.2 and earlier Missing Authorization via profile Action
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
CamaleonCMS version 2.9.2 and earlier contains a missing authorization vulnerability in the admin users controller that allows any authenticated user to access any other user's profile data by supplying an arbitrary user ID parameter. Attackers can send a GET request to the admin profile endpoint with an enumerable sequential integer user ID to disclose profile information of any user, including administrators, due to the profile action being excluded from the role validation filter with no compensating ownership check.
| CWE | CWE-862 |
| Vendor | owen2345 |
| Product | camaleoncms |
| Published | Aug 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for owen2345 camaleoncms
Be the first to know when new medium vulnerabilities affecting owen2345 camaleoncms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected Versions
owen2345 / CamaleonCMS
0 โค 2.9.2
References
github.com: https://github.com/owen2345/camaleon-cms/pull/1197 github.com: https://github.com/owen2345/camaleon-cms github.com: https://github.com/owen2345/camaleon-cms/commit/ae10da7cfce902a8552927c57b0a562fb1676040 vulncheck.com: https://www.vulncheck.com/advisories/camaleoncms-and-earlier-missing-authorization-via-profile-action
Credits
Saidakbarxon Maxsudxonov