Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-67616— Camaleon CMS 2.9.2 Missing Authorization via /admin/post_type drafts endpoint

CVSS 4.3 · Medium EPSS 0.25% · P17

Possible ATT&CK Techniques 1AI

T1078.002 · Domain Accounts

Affected Version Matrix 2

VendorProductVersion RangeStatus
owen2345camaleon-cms≤ 2.9.2affected
88ab703b5ac041afb93a9993470aa366093c5311unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-67616

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Camaleon CMS 2.9.2 Missing Authorization via /admin/post_type drafts endpoint
Source: CVE Program / CVE List V5
Vulnerability Description
Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoint that allows any authenticated low-privileged user to create draft posts by bypassing role and permission checks. Attackers can send requests to the drafts endpoint using only session authentication to create unauthorized drafts that appear in the administrative drafts queue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5
Vulnerability Title
Owen Peredo Diaz CAMALEON CMS 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Owen Peredo Diaz CAMALEON CMS是Owen Peredo Diaz个人开发者开源的一款内容管理系统。 Owen Peredo Diaz CAMALEON CMS 2.9.2及之前版本存在授权问题漏洞,该漏洞源于drafts端点缺少授权验证,可能导致任何经过身份验证的低权限用户绕过角色和权限检查,创建未授权草稿并出现在管理草稿队列中。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
owen2345camaleon-cms 0 ~ 2.9.2 -

II. Public POCs for CVE-2026-67616

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-67616

登录查看更多情报信息。

Patches & Fixes for CVE-2026-67616 (1)

Vendor Advisories for CVE-2026-67616 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-67616

No comments yet


Leave a comment