Junglewise Threat Intelligence

CVE-2026-56721: CamaleonCMS privilege escalation via insecure direct object reference

CVE-2026-56721 · Severity: high · CVSS 8.8 · Published 2026-08-11

Executive brief

CamaleonCMS is a Ruby on Rails-based content management system used to manage website content and user accounts. An authenticated attacker with low-level privileges can exploit a parameter confusion flaw to overwrite any user's credentials, including administrator accounts, leading to complete site takeover and unauthorized access to all managed content and administrative functions.

Technical details

A privilege escalation vulnerability exists in the UsersController's updated_ajax endpoint due to parameter confusion between the authorization filter and the action body. The vulnerability is an insecure direct object reference (IDOR) where the authorization filter checks params[:id] against the current user's ID, but the controller action uses params[:user_id] to load and mutate the target user record. An authenticated attacker can send a PATCH request setting params[:id] to their own user ID (passing authorization) while setting params[:user_id] to a victim's ID, allowing credential overwrite including admin passwords. No authentication bypass is required—the attacker must already be authenticated. Patches are available in the repository after the vulnerability fix commit.

Affected products

  • Owen2345 CamaleonCMS 2.9.2 and earlier

Timeline

  • 2026-08-11: disclosed
  • patched: Fix available in repository commit 26345034523a505cb01615509b7f0a665e89ae3e

References