CVE-2026-67616
Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoint that allows any authenticated low-privileged user to create draft posts by bypassing role and permission checks. Attackers can send requests to the drafts endpoint using only session authentication to create unauthorized drafts that appear in the administrative drafts queue.
- Affected products
- Camaleon Cms
- Fix
- Available
- CVSS 4.0
- 5.3 MEDIUM
- CVSS 3.1
- 4.3 MEDIUM
- EPSS
- 0.3% (17th percentile)
- Weakness
- CWE-862
- NVD status
- Received
- Published
- 2026-08-03
CVE-2026-67616 at NVD
No indexed exploits for CVE-2026-67616 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-67616 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.