Executive brief
Camaleon CMS is a content management system built on Ruby on Rails. A security flaw in its AWS S3 storage component allows logged-in users, even those with low privileges, to access sensitive files on the web server's filesystem. This could lead to the exposure of critical system information, such as user credentials or configuration files.
Technical details
A path traversal vulnerability (CWE-22) exists in the CamaleonCmsAwsUploader backend of Camaleon CMS. The issue resides in the download_private_file functionality, where the AWS uploader fails to validate file paths using the valid_folder_path? method, unlike the local uploader implementation. An authenticated attacker can provide directory traversal sequences (e.g., ../) via the 'file' parameter to bypass directory restrictions. This allows for the retrieval of sensitive files like /etc/passwd. This vulnerability is a bypass of an incomplete fix for a previous issue (CVE-2024-46987) and has been addressed in commit f54a77e.
Affected products
- owen2345 Camaleon CMS 2.4.5.0 through 2.9.0
Timeline
- 2026-03-08: disclosed: Pull request submitted to fix the vulnerability
- 2026-03-09: patched: Fix merged into master branch via commit f54a77e
- 2026-03-10: advisory: CVE-2026-1776 published