{"id":"CVE-2026-1776","title":"Camaleon CMS versions 2.4.5.0 through 2.9.0, prior to commit f54a77e, contain a path traversal vulnerability in the AWS S3 uploader implementation that allows authenticated users to read arbitrary files from the web server’s filesystem","summary":"Camaleon CMS versions 2.4.5.0 through 2.9.0, prior to commit f54a77e, contain a path traversal vulnerability in the AWS S3 uploader implementation that allows authenticated users to read arbitrary files from the web server’s filesystem. …","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-22"],"vendor":"tuzitio","product":"camaleon_cms","affected":["camaleon_cms >= 2.4.5, <= 2.9.0"],"published":"2026-03-10","updated":"2026-10-08","sourceUpdated":"2026-10-08T16:17:10.647","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-1776","references":[{"url":"https://camaleon.website/","label":"disclosure@vulncheck.com"},{"url":"https://github.com/owen2345/camaleon-cms/commit/f54a77e2a7be601215ea1b396038c589a0cab9af","label":"disclosure@vulncheck.com"},{"url":"https://github.com/owen2345/camaleon-cms/pull/1127","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/camaleon-cms-aws-uploader-authenticated-path-traversal-arbitrary-file-read","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-03-10T14:57:09.790742Z"},"scores":{"nvd":6.5,"cna":6},"epss":0.0076,"epssPercentile":0.53877,"ingestedAt":"2026-10-08T16:52:14.674Z","slug":"CVE-2026-1776","body":"## Overview\n\nCamaleon CMS versions 2.4.5.0 through 2.9.0, prior to commit f54a77e, contain a path traversal vulnerability in the AWS S3 uploader implementation that allows authenticated users to read arbitrary files from the web server’s filesystem. The issue occurs in the download_private_file functionality when the application is configured to use the CamaleonCmsAwsUploader backend. Unlike the local uploader implementation, the AWS uploader does not validate file paths with valid_folder_path?, allowing directory traversal sequences to be supplied via the file parameter. As a result, any authenticated user, including low-privileged registered users, can access sensitive files such as /etc/passwd. This issue represents a bypass of the incomplete fix for CVE-2024-46987 and affects deployments using the AWS S3 storage backend.\n\n## Affected\n\n- `camaleon_cms >= 2.4.5, <= 2.9.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}