CVE-2026-10715 MEDIUM

CVE-2026-10715: Camaleon CMS 2.9.2 - Improper authorization in draft autosave endpoint

Vendor Camaleon Cms
Product Camaleon CMS
Weakness CWE-862 · Missing authorization
Published June 12, 2026
Last update June 12, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Camaleon CMS 2.9.2 contains an improper authorization vulnerability in the administrator draft autosave endpoint. A low-privileged authenticated user can send an arbitrary post_id to POST /admin/post_type/<POST_TYPE_ID>/drafts and overwrite the draft associated with another user's post.

Key dates

02Disclosure timeline

June 12, 2026 CVE published
June 12, 2026 Record updated