CVE-2026-102261 | owen2345 Camaleon CMS up to 2.9.2 Media Crop media_controller.rb crop saved_avatar authorization
A vulnerability marked as problematic has been reported in owen2345 Camaleon CMS up to 2.9.2. Impacted is the function crop of the file app/controllers/camaleon_cms/admin/media_controller.rb of the component Media Crop Handler. This manipulation of the argument saved_avatar causes authorization bypass.
This vulnerability appears as CVE-2026-102261. The attack may be initiated remotely. In addition, an exploit is available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More