---
id: CVE-2026-102261
title: A flaw has been found in owen2345 Camaleon CMS up to 2.9.2
summary: >-
  A flaw has been found in owen2345 Camaleon CMS up to 2.9.2. Impacted is the
  function crop of the file
  app/controllers/camaleon_cms/admin/media_controller.rb of the component Media
  Crop Handler. This manipulation of the argument saved_ava…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'
cwe:
  - CWE-285
  - CWE-639
vendor: owen2345
product: Camaleon CMS
affected:
  - camaleon_cms 2.9.0
  - camaleon_cms 2.9.1
  - camaleon_cms 2.9.2
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T05:16:58.683'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102261'
references:
  - url: >-
      https://github.com/owen2345/camaleon-cms/commit/c143e145caa600947e70a240e87f2fed889149d3
    label: cna@vuldb.com
  - url: 'https://github.com/owen2345/camaleon-cms/releases/tag/2.9.3'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-102261'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/934944'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/411164'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/411164/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T04:27:15.488Z'
---

## Overview

A flaw has been found in owen2345 Camaleon CMS up to 2.9.2. Impacted is the function crop of the file app/controllers/camaleon_cms/admin/media_controller.rb of the component Media Crop Handler. This manipulation of the argument saved_avatar causes authorization bypass. The attack may be initiated remotely. The exploit has been published and may be used. Upgrading to version 2.9.3 is recommended to address this issue. Patch name: c143e145caa600947e70a240e87f2fed889149d3. It is suggested to upgrade the affected component.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
