CVE-2026-73326 PUBLISHED

CamaleonCMS Missing Authorization via Plugin Administration Endpoints

Assigner: VulnCheck
Reserved: 11.08.2026 Published: 12.08.2026 Updated: 12.08.2026

CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access and modify plugin settings by reaching four unprotected plugin-administration endpoints without administrator-level authorization. Attackers can manipulate plugin configuration parameters at runtime across the attack, front_cache, cama_meta_tag, and cama_contact_form plugins to alter cached page behavior, modify public meta-tag output, or reconfigure contact forms, enabling account takeover when chained with stored cross-site scripting through the contact form's before_html field.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N
CVSS Score: 7.2

Product Status

Vendor owen2345
Product CamaleonCMS
Versions Default: affected
  • affected from 0 to 2.9.1 (incl.)

Credits

  • Amir Aliu & Enrik Mustafa finder

References

Problem Types

  • Missing Authorization CWE