CVE-2026-102261
5.4 MEDIUMpublic exploit availablePublished 2026-09-29 · Updated 2026-09-29
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
A flaw has been found in owen2345 Camaleon CMS up to 2.9.2. Impacted is the function crop of the file app/controllers/camaleon_cms/admin/media_controller.rb of the component Media Crop Handler. This manipulation of the argument saved_avatar causes authorization bypass. The attack may be initiated remotely. The exploit has been published and may be used. Upgrading to version 2.9.3 is recommended to address this issue. Patch name: c143e145caa600947e70a240e87f2fed889149d3. It is suggested to upgrade the affected component.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Weaknesses
CWE-285, CWE-639
Public exploit & PoC references
All references
- https://github.com/owen2345/camaleon-cms/commit/c143e145caa600947e70a240e87f2fed889149d3
- https://github.com/owen2345/camaleon-cms/releases/tag/2.9.3
- https://vuldb.com/cve/CVE-2026-102261
- https://vuldb.com/submit/934944
- https://vuldb.com/vuln/411164
- https://vuldb.com/vuln/411164/cti
- https://vuldb.com/submit/934944
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-100878PoC
- HIGHCVE-2026-100885PoC
- MEDIUMCVE-2026-100897
- LOWCVE-2026-102844PoC
- MEDIUMCVE-2026-18818
- MEDIUMCVE-2026-79917PoC
- MEDIUMCVE-2026-83805PoC
- MEDIUMCVE-2026-93955PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.