Description
CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access and modify plugin settings by reaching four unprotected plugin-administration endpoints without administrator-level authorization. Attackers can manipulate plugin configuration parameters at runtime across the attack, front_cache, cama_meta_tag, and cama_contact_form plugins to alter cached page behavior, modify public meta-tag output, or reconfigure contact forms, enabling account takeover when chained with stored cross-site scripting through the contact form's before_html field.
Published: 2026-08-12
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CamaleonCMS permits any authenticated low‑privileged user to access four unprotected plugin‑administration endpoints and modify settings for the attack_cache, front_cache, cama_meta_tag and cama_contact_form plugins. This missing authorization flaw allows the attacker to alter cached page behavior, change public meta‑tag output and reconfigure contact form fields. When combined with stored cross‑site scripting through the contact form’s before_html field, the attacker can achieve account takeover. The weakness is a classic example of missing authorization (CWE‑862).

Affected Systems

The affected product is CamaleonCMS by owen2345. The CVE lists no specific version information, so any release that still contains the four unprotected endpoints is vulnerable. The flaw is present on the plugin‑administration URLs handling attack_cache, front_cache, cama_meta_tag and cama_contact_form configuration changes.

Risk and Exploitability

With a CVSS score of 7.2 the vulnerability is considered medium‑high severity. No EPSS score is available, indicating no known exploitation probability data. The flaw is not listed in CISA KEV. Attackers must be authenticated but do not need administrator privileges; they can simply send HTTP requests to the vulnerable endpoints to modify plugin settings, and can chain the XSS component to elevate privilege or compromise accounts.

Generated by OpenCVE AI on August 12, 2026 at 23:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest CamaleonCMS release that contains the authorization fix for the plugin configuration endpoints
  • Restrict HTTP access to the attack_cache, front_cache, cama_meta_tag and cama_contact_form administration routes so that only users with administrator privileges can reach them
  • If upgrading immediately is not possible, remove or disable the vulnerable plugins until the patch is applied and implement additional input validation or CSP rules to mitigate the stored XSS component

Generated by OpenCVE AI on August 12, 2026 at 23:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Owen2345
Owen2345 camaleon Cms
Vendors & Products Owen2345
Owen2345 camaleon Cms

Wed, 12 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access and modify plugin settings by reaching four unprotected plugin-administration endpoints without administrator-level authorization. Attackers can manipulate plugin configuration parameters at runtime across the attack, front_cache, cama_meta_tag, and cama_contact_form plugins to alter cached page behavior, modify public meta-tag output, or reconfigure contact forms, enabling account takeover when chained with stored cross-site scripting through the contact form's before_html field.
Title CamaleonCMS Missing Authorization via Plugin Administration Endpoints
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L'}

cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Owen2345 Camaleon Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-12T19:29:26.426Z

Reserved: 2026-08-11T21:47:14.059Z

Link: CVE-2026-73326

cve-icon Vulnrichment

Updated: 2026-08-12T19:29:23.041Z

cve-icon NVD

Status : Received

Published: 2026-08-12T20:17:54.887

Modified: 2026-08-12T20:17:54.887

Link: CVE-2026-73326

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T23:30:10Z

Weaknesses