SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-67616

MEDIUM · CVSS 4.3 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-03 · Last synced 2026-09-02

CyberRota Analysis

AI-Generated

Camaleon CMS versions up to 2.9.2 are vulnerable due to a missing authorization flaw in the drafts endpoint, allowing authenticated low-privileged users to create unauthorized draft posts by bypassing role and permission checks. This could lead to unauthorized content appearing in the administrative drafts queue, potentially disrupting content management processes. Organizations using Camaleon CMS should prioritize patching this vulnerability to prevent exploitation by malicious users.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-67616
Severity
MEDIUM
CVSS
4.3
EPSS
0.25%

Original NVD Description

Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoint that allows any authenticated low-privileged user to create draft posts by bypassing role and permission checks. Attackers can send requests to the drafts endpoint using only session authentication to create unauthorized drafts that appear in the administrative drafts queue.