---
id: CVE-2026-86100
title: >-
  Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect targets
  when fetching remote files in the Upload from URL media feature
summary: >-
  Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect targets
  when fetching remote files in the Upload from URL media feature. Authenticated
  attackers can supply URLs that pass initial validation but redirect to
  internal ne…
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-918
vendor: owen2345
product: camaleon_cms
affected:
  - camaleon_cms >= 2.7.5 < 2.9.2
published: '2026-09-05'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:05:53.177'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86100'
references:
  - url: 'https://github.com/owen2345/camaleon-cms'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/owen2345/camaleon-cms/blob/2.9.1/app/helpers/camaleon_cms/uploader_helper.rb
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/owen2345/camaleon-cms/commit/3c46b6e512518ded476226162305c8eae00aac3f
    label: disclosure@vulncheck.com
  - url: 'https://github.com/owen2345/camaleon-cms/pull/1133'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/owen2345/camaleon-cms/releases/tag/2.9.2'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/camaleon-cms-2.7.5-through-2.9.1-ssrf-via-http-redirect-in-upload-from-url
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-08T17:59:11.378252Z'
epss: 0.0032
epssPercentile: 0.2228
ingestedAt: '2026-09-08T19:08:49.595Z'
---

## Overview

Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect targets when fetching remote files in the Upload from URL media feature. Authenticated attackers can supply URLs that pass initial validation but redirect to internal network addresses, allowing server-side request forgery to internal services.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
