MEDIUM
owen2345
CVE published 2026-08-03
CVE-2026-67616
CVE-2026-67616 is a missing authorization vulnerability in Camaleon CMS versions through 2.9.2. The issue allows authenticated low-privileged users to create draft posts by bypassing role and permission checks on the drafts endpoint. This vulnerability can be exploited by sending requests to the drafts endpoint using only session authentication, potentially leading to unauthorized drafts appearing in the [truncated]