Junglewise Threat Intelligence

CVE-2026-10715: Camaleon CMS improper authorization in draft autosave endpoint

CVE-2026-10715 · Severity: info · CVSS 5.1 · Published 2026-06-12

Technologies: Camaleon Cms.

Executive brief

Camaleon CMS, a content management system built on Ruby on Rails, contains a security flaw in its administrative draft saving feature. An authorized user with low-level permissions can exploit this to overwrite the saved drafts of other users, including those belonging to administrators. This could lead to the loss of original content or the unauthorized modification of pending website updates.

Technical details

An improper authorization vulnerability (CWE-862) exists in Camaleon CMS 2.9.2 within the administrator draft autosave endpoint. The application fails to validate if the authenticated user has the rights to modify a specific post when sending a request to the POST /admin/post_type/<POST_TYPE_ID>/drafts endpoint. By supplying an arbitrary post_id, a low-privileged authenticated attacker can overwrite the draft content associated with any other user's post. This attack requires network access and valid low-privileged credentials.

Affected products

  • Camaleon CMS Camaleon CMS 2.9.2

Timeline

  • 2026-06-12: disclosed
  • 2026-06-12: advisory

References