๐Ÿ” CVE Alert

CVE-2026-56720

MEDIUM 4.3

CamaleonCMS 2.9.2 and earlier Missing Authorization via profile Action

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

CamaleonCMS version 2.9.2 and earlier contains a missing authorization vulnerability in the admin users controller that allows any authenticated user to access any other user's profile data by supplying an arbitrary user ID parameter. Attackers can send a GET request to the admin profile endpoint with an enumerable sequential integer user ID to disclose profile information of any user, including administrators, due to the profile action being excluded from the role validation filter with no compensating ownership check.

CWE CWE-862
Vendor owen2345
Product camaleoncms
Published Aug 11, 2026
Stay Ahead of the Next One

Get instant alerts for owen2345 camaleoncms

Be the first to know when new medium vulnerabilities affecting owen2345 camaleoncms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

owen2345 / CamaleonCMS
0 โ‰ค 2.9.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/owen2345/camaleon-cms/pull/1197 github.com: https://github.com/owen2345/camaleon-cms github.com: https://github.com/owen2345/camaleon-cms/commit/ae10da7cfce902a8552927c57b0a562fb1676040 vulncheck.com: https://www.vulncheck.com/advisories/camaleoncms-and-earlier-missing-authorization-via-profile-action

Credits

Saidakbarxon Maxsudxonov