CVE-2026-102261 Details
Description
A flaw has been found in owen2345 Camaleon CMS up to 2.9.2. Impacted is the function crop of the file app/controllers/camaleon_cms/admin/media_controller.rb of the component Media Crop Handler. This manipulation of the argument saved_avatar causes authorization bypass. The attack may be initiated remotely. The exploit has been published and may be used. Upgrading to version 2.9.3 is recommended to address this issue. Patch name: c143e145caa600947e70a240e87f2fed889149d3. It is suggested to upgrade the affected component.
An authorization bypass vulnerability has been identified in Camaleon CMS versions through 2.9.2. The issue resides in the Media Crop Handler, specifically within the crop function of the media_controller.rb file. The vulnerability allows a user with only media management permissions to overwrite any same-site user's avatar, including that of an administrator. This is achieved by manipulating the saved_avatar parameter to bypass authorization checks. The vulnerability can be exploited remotely.
Users are advised to upgrade to Camaleon CMS version 2.9.3, which addresses this vulnerability by requiring the 'manage, users' permission to crop another user's avatar. After updating, roles that need to manage user avatars should be granted the 'manage, users' permission.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://vuldb.com/submit/934944 | CISA-ADP | Issue TrackingPermission Required |
| https://github.com/owen2345/camaleon-cms/commit/c143e145caa600947e70a240e87f2fed889149d3 | [email protected] | Source CodeVendor |
| https://github.com/owen2345/camaleon-cms/releases/tag/2.9.3 | [email protected] | Release NotesVendor |
| https://vuldb.com/cve/CVE-2026-102261 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/934944 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/411164 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/411164/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-285 | Improper Authorization | [email protected] |
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| owen2345 Camaleon CMS | <= 2.9.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion