Sploitus

CVE-2026-67616

No indexed exploits for CVE-2026-67616 yet

Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoint that allows any authenticated low-privileged user to create draft posts by bypassing role and permission checks. Attackers can send requests to the drafts endpoint using only session authentication to create unauthorized drafts that appear in the administrative drafts queue.

Affected products
Camaleon Cms
Fix
Available
CVSS 4.0
5.3 MEDIUM
CVSS 3.1
4.3 MEDIUM
EPSS
0.3% (17th percentile)
Weakness
CWE-862
NVD status
Received
Published
2026-08-03
CVE-2026-67616 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-67616 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-67616 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.