Executive brief
Camaleon CMS, a content management system built on Ruby on Rails, contains a security flaw in its administrative draft saving feature. An authorized user with low-level permissions can exploit this to overwrite the saved drafts of other users, including those belonging to administrators. This could lead to the loss of original content or the unauthorized modification of pending website updates.
Technical details
An improper authorization vulnerability (CWE-862) exists in Camaleon CMS 2.9.2 within the administrator draft autosave endpoint. The application fails to validate if the authenticated user has the rights to modify a specific post when sending a request to the POST /admin/post_type/<POST_TYPE_ID>/drafts endpoint. By supplying an arbitrary post_id, a low-privileged authenticated attacker can overwrite the draft content associated with any other user's post. This attack requires network access and valid low-privileged credentials.
Affected products
- Camaleon CMS Camaleon CMS 2.9.2
Timeline
- 2026-06-12: disclosed
- 2026-06-12: advisory