CVE-2026-67616
Last modified
CVE-2026-67616 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoint that allows any authenticated low-privileged user to create draft posts by bypassing role and permission checks. Attackers can send requests to the drafts endpoint using only session authentication to create unauthorized drafts that appear in the administrative drafts queue.. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoint that allows any authenticated low-privileged user to create draft posts by bypassing role and permission checks. Attackers can send requests to the drafts endpoint using only session authentication to create unauthorized drafts that appear in the administrative drafts queue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| owen2345 | camaleon-cms | <= 2.9.2 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-67616?
How severe is CVE-2026-67616?
How do I fix CVE-2026-67616?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-67608Telenia Software TVox 26.5.3 and prior 26.x versions, and 24…8.6
- CVE-2026-67609Telenia Software TVox 26.5.3 and prior 26.x versions, and 24…8.5
- CVE-2026-6761Privilege escalation in the Networking component. This vulne…8.8
- CVE-2026-67610OpenEMR through 8.2.0 contains an improper authentication vu…8.1
- CVE-2026-67611OpenEMR through 8.2.0 contains an authentication bypass vuln…8.6
- CVE-2026-67612OpenEMR through 8.2.0 contains a stored cross-site scripting…4.8
- CVE-2026-67617Microweber CMS through 2.0.20 contains a stored cross-site s…4.8
- CVE-2026-67618marimo before 0.23.15 contains a configuration injection vul…6.5
- CVE-2026-6762Spoofing issue in the DOM: Core & HTML component. This vulne…6.3
- CVE-2026-67620Flowise through 3.1.4 contains a server-side request forgery…7.7
- CVE-2026-67621Flowise through 3.1.4 contains a missing authorization vulne…7.6
- CVE-2026-67622Flowise through 3.1.4 contains an insecure direct object ref…9.9
Are you affected by CVE-2026-67616?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
