Camaleon CMS 2.9.2 contains an improper authorization
Published: June 12, 2026
SECURITY IDENTIFIERS
- CVE: CVE-2026-10715 (NVD)
- GHSA: GHSA-vg43-9r8m-q2cc
GEM
UNAFFECTED VERSIONS
< 2.9.2
PATCHED VERSIONS
>= 2.9.3
DESCRIPTION
Camaleon CMS 2.9.2 contains an improper authorization vulnerability in the administrator draft autosave endpoint. A low-privileged authenticated user can send an arbitrary post_id to POST /admin/post_type/<POST_TYPE_ID>/drafts and overwrite the draft associated with another user's post.
RELATED
- https://nvd.nist.gov/vuln/detail/CVE-2026-10715
- https://rubygems.org/gems/camaleon_cms/versions/2.9.3
- https://github.com/owen2345/camaleon-cms/releases/tag/2.9.3
- https://github.com/owen2345/camaleon-cms/pull/1196
- https://fluidattacks.com/es/advisories/billie
- https://github.com/advisories/GHSA-vg43-9r8m-q2cc
