CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-67616

mediumCVSS 4.3covered by 1 sourcefirst seen 2026-08-03
Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoint that allows any authenticated low-privileged user to create draft posts by bypassing role and permission checks. Attackers can send requests to the drafts endpoint using only session authentication to create unauthorized drafts that appear in the administrative drafts queue.

⚡ Watch CVE-2026-67616

Get an email if CVE-2026-67616 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-67616

CVE.org record

Embed the live status

CVE-2026-67616 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-67616 status](https://www.csirts.com/badge/CVE-2026-67616)](https://www.csirts.com/cve/CVE-2026-67616)