CVE-2026-102261
Deferred Deferred - Pending Action

Authorization Bypass in Camaleon CMS via Media Crop Handler

Vulnerability report for CVE-2026-102261, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulDB

Description

A flaw has been found in owen2345 Camaleon CMS up to 2.9.2. Impacted is the function crop of the file app/controllers/camaleon_cms/admin/media_controller.rb of the component Media Crop Handler. This manipulation of the argument saved_avatar causes authorization bypass. The attack may be initiated remotely. The exploit has been published and may be used. Upgrading to version 2.9.3 is recommended to address this issue. Patch name: c143e145caa600947e70a240e87f2fed889149d3. It is suggested to upgrade the affected component.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
owen2345 camaleon_cms to 2.9.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-102261 is an authorization bypass flaw in Camaleon CMS versions up to 2.9.2. The vulnerability exists in the Media Crop Handler component, specifically in the crop function of the file app/controllers/camaleon_cms/admin/media_controller.rb. It allows a media-only role with manage media permissions to overwrite another user's avatar, including an administrator's, by exploiting the saved_avatar parameter in the MediaController#crop endpoint. This occurs because the endpoint lacks proper object-level authorization checks for non-self targets.

Detection Guidance

Check if your Camaleon CMS version is below 2.9.3. Run: gem list camaleon-cms or check the version in the admin panel. Inspect network traffic for unauthorized POST requests to /admin/media/crop with saved_avatar parameter targeting non-self users. Review logs for media-only roles attempting to modify avatars of administrators or other users.

Impact Analysis

This vulnerability allows unauthorized users with media permissions to overwrite avatars of other users, including administrators. This could lead to impersonation attacks, unauthorized access to sensitive data, or further exploitation of the system. Attackers could use this to gain elevated privileges or disrupt normal operations by replacing legitimate avatars with malicious content.

Compliance Impact

This vulnerability allows unauthorized users with media-only roles to overwrite avatars, including administrators, potentially leading to unauthorized access or impersonation. Such authorization bypasses could violate GDPR's integrity and confidentiality requirements or HIPAA's access controls, depending on the data processed by the CMS.

Mitigation Strategies

Upgrade Camaleon CMS to version 2.9.3 or later immediately. Review and adjust role permissions to ensure media-only roles do not have unnecessary access to user avatar management. Monitor for suspicious activity in media and user management endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102261. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart