CVE-2026-67616: Missing Authorization in owen2345 camaleon-cms
Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoint that allows any authenticated low-privileged user to create draft posts by bypassing role and permission checks. Attackers can send requests to the drafts endpoint using only session authentication to create unauthorized drafts that appear in the administrative drafts queue.
AI Analysis
Technical Summary
CVE-2026-67616 describes a missing authorization vulnerability in Camaleon CMS through version 2.9.2. The vulnerability exists on the drafts endpoint, where authenticated low-privileged users can bypass role and permission checks to create draft posts. This is possible by sending requests authenticated only with a valid session, allowing unauthorized draft creation that appears in the administrative drafts queue. The vulnerability was fixed in commit 88ab703. No official remediation level or patch link is provided in the data, but the fix is referenced by the commit identifier.
Potential Impact
An attacker with any authenticated low-privileged account can create draft posts without proper authorization. These unauthorized drafts appear in the administrative drafts queue, potentially leading to unauthorized content injection or workflow disruption. The vulnerability does not allow privilege escalation or direct administrative access but could be leveraged to interfere with content management processes.
Mitigation Recommendations
A fix is available as indicated by the referenced commit 88ab703. Users should upgrade Camaleon CMS to a version that includes this commit or later. Since no official patch link or advisory is provided, users should consult the vendor's repository or official channels to apply the fix. Until patched, restrict authenticated user permissions as much as possible to limit exploitation potential.
CVE-2026-67616: Missing Authorization in owen2345 camaleon-cms
Description
Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoint that allows any authenticated low-privileged user to create draft posts by bypassing role and permission checks. Attackers can send requests to the drafts endpoint using only session authentication to create unauthorized drafts that appear in the administrative drafts queue.
CVSS v4.0
Score 5.3medium
Affected software
owen2345
camaleon-cms
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-67616 describes a missing authorization vulnerability in Camaleon CMS through version 2.9.2. The vulnerability exists on the drafts endpoint, where authenticated low-privileged users can bypass role and permission checks to create draft posts. This is possible by sending requests authenticated only with a valid session, allowing unauthorized draft creation that appears in the administrative drafts queue. The vulnerability was fixed in commit 88ab703. No official remediation level or patch link is provided in the data, but the fix is referenced by the commit identifier.
Potential Impact
An attacker with any authenticated low-privileged account can create draft posts without proper authorization. These unauthorized drafts appear in the administrative drafts queue, potentially leading to unauthorized content injection or workflow disruption. The vulnerability does not allow privilege escalation or direct administrative access but could be leveraged to interfere with content management processes.
Mitigation Recommendations
A fix is available as indicated by the referenced commit 88ab703. Users should upgrade Camaleon CMS to a version that includes this commit or later. Since no official patch link or advisory is provided, users should consult the vendor's repository or official channels to apply the fix. Until patched, restrict authenticated user permissions as much as possible to limit exploitation potential.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-07-29T21:07:39.203Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a71103cbf32cb7a344d9fc5
Added to database: 08/03/2026, 22:03:40 UTC
Last enriched: 08/11/2026, 17:55:46 UTC
Last updated: 09/18/2026, 02:33:03 UTC
Views: 39
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.