Sploitus

CVE-2026-56721

No indexed exploits for CVE-2026-56721 yet

CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object reference (IDOR) that allows authenticated low-privileged attackers to overwrite any user's credentials by exploiting a parameter confusion flaw between the authorization filter and action body in the UsersController. Attackers can send a PATCH request to the updated_ajax endpoint setting params[:id] to their own user ID to pass the self-authorization check while simultaneously setting params[:user_id] to a victim's ID, causing the controller to load and mutate the victim's account, including overwriting administrator passwords to achieve full site takeover.

Affected products
Camaleon Cms
Fix
Available
CVSS 3.1
8.8 HIGH
EPSS
0.4% (29th percentile)
Weakness
CWE-639
NVD status
Received
Published
2026-08-11
CVE-2026-56721 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-56721 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-56721 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.