Sceawere

Vulnerability Detail

CVE-2026-102261UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Camaleon CMS Authorization Bypass Flaw

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
2h ago
Vendor
owen2345
Product
Camaleon CMS
Attack Type
Authorization Bypass
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A flaw has been found in owen2345 Camaleon CMS up to 2.9.2. Impacted is the function crop of the file app/controllers/camaleon_cms/admin/media_controller.rb of the component Media Crop Handler. This manipulation of the argument saved_avatar causes authorization bypass. The attack may be initiated remotely. The exploit has been published and may be used. Upgrading to version 2.9.3 is recommended to address this issue. Patch name: c143e145caa600947e70a240e87f2fed889149d3. It is suggested to upgrade the affected component.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-09-29T05:16:57.380Z",
  "pubdate": "2026-09-29T05:16:57.380Z",
  "executiveSummary": "A critical authorization bypass vulnerability has been identified in the Media Crop Handler component of Camaleon CMS, affecting versions up to 2.9.2.\nThe vulnerability resides within the 'crop' function of 'app/controllers/camaleon_cms/admin/media_controller.rb', where improper handling of the 'saved_avatar' parameter permits unauthorized access.\nThis flaw allows remote, unauthenticated, or low-privileged attackers to manipulate internal application logic, potentially leading to unauthorized data processing or administrative actions via the media handling interface.\nThe risk is categorized as high, particularly as the exploit has been publicly disclosed, increasing the likelihood of malicious exploitation.\nOrganizations using Camaleon CMS should prioritize upgrading to version 2.9.3 to mitigate this risk, as the patch specifically addresses the insecure parameter validation within the affected controller.",
  "technicalDetails": "The vulnerability is an authorization bypass flaw located in the 'crop' function within 'app/controllers/camaleon_cms/admin/media_controller.rb'. The root cause stems from insufficient server-side validation of the 'saved_avatar' argument during the media cropping process.\nIn the affected versions (up to 2.9.2), the application fails to properly enforce access control checks when the 'saved_avatar' parameter is processed. An attacker can supply a crafted 'saved_avatar' value to the media controller to manipulate the execution flow of the cropping function. Because the function does not verify the user's authorization level or the legitimacy of the request context relative to the specified resource, the application proceeds to execute the requested action despite the lack of necessary permissions.\nThe attack flow begins with a remote attacker sending a specially crafted HTTP request targeting the Media Crop Handler. By manipulating the 'saved_avatar' argument, the attacker bypasses the security checks intended to gatekeep the file processing functionality. Since this component is responsible for handling media operations, successful exploitation allows an attacker to interact with the file system or application data in ways that are strictly prohibited for unauthorized or standard users.\nThe 'crop' function is expected to validate session state and resource ownership prior to performing any image modifications or data persistence. By failing to validate the input against the current user context, the controller becomes vulnerable to unauthorized state changes. The exploit leverages this weakness to circumvent the intended security boundaries of the CMS. As the exploit is publicly available, the attack vector is well-understood, enabling potential automated or manual exploitation by remote actors.\nThe vulnerability indicates a failure in secure coding practices related to input validation and session-based access control. The patch identified as 'c143e145caa600947e70a240e87f2fed889149d3' effectively remediates this by introducing strict checks to the affected controller, ensuring that parameters passed to the 'crop' function are validated against the requestor's authorization tokens and existing access policies, thereby closing the bypass vector."
}
CVE-2026-102261: Camaleon CMS Authorization Bypass Flaw (MEDIUM Severity, CVSS: 5.4) | Sceawere