CVE-2026-1776

Source
https://cve.org/CVERecord?id=CVE-2026-1776
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-1776.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-1776
Aliases
Published
2026-03-10T07:38:01.950Z
Modified
2026-04-10T05:38:08.271688Z
Severity
  • 6.0 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

Camaleon CMS versions 2.4.5.0 through 2.9.0, prior to commit f54a77e, contain a path traversal vulnerability in the AWS S3 uploader implementation that allows authenticated users to read arbitrary files from the web server’s filesystem. The issue occurs in the downloadprivatefile functionality when the application is configured to use the CamaleonCmsAwsUploader backend. Unlike the local uploader implementation, the AWS uploader does not validate file paths with validfolderpath?, allowing directory traversal sequences to be supplied via the file parameter. As a result, any authenticated user, including low-privileged registered users, can access sensitive files such as /etc/passwd. This issue represents a bypass of the incomplete fix for CVE-2024-46987 and affects deployments using the AWS S3 storage backend.

References

Affected packages

Git / github.com/owen2345/camaleon-cms

Affected ranges

Type
GIT
Repo
https://github.com/owen2345/camaleon-cms
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "2.4.5.0"
        },
        {
            "last_affected": "2.9.0"
        }
    ]
}

Affected versions

0.*
0.1.7
0.2.0
2.*
2.1.1
2.1.2
2.1.2.0
2.2.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.4.0
2.4.1
2.4.2
2.4.3
2.4.3.10
2.4.3.11
2.4.3.12
2.4.3.7
2.4.4
2.4.4.2
2.4.4.3
2.4.4.5
2.4.4.6
2.4.5
2.4.5.1
2.4.5.10
2.4.5.11
2.4.5.12
2.4.5.13
2.4.5.14
2.4.5.7
2.4.6.0
2.4.6.1
2.4.6.7
2.5.1
2.5.3
2.5.3.1
2.6.0
2.6.0.1
2.6.1
2.6.2
2.6.4
2.7.0
2.7.1
2.7.3
2.7.4
2.7.5
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.1
camaleon_cms-2.*
camaleon_cms-2.4.5.11.gem
v2.*
v2.0.0
v2.1.1.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-1776.json"