CVE-2026-86100

Source
https://cve.org/CVERecord?id=CVE-2026-86100
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86100.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-86100
Published
2026-09-04T23:16:23.223Z
Modified
2026-09-06T03:47:20.616984059Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Camaleon CMS 2.7.5 through 2.9.1 SSRF via HTTP Redirect in Upload from URL
Details

Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect targets when fetching remote files in the Upload from URL media feature. Authenticated attackers can supply URLs that pass initial validation but redirect to internal network addresses, allowing server-side request forgery to internal services.

Database specific
{
    "cwe_ids": [
        "CWE-918"
    ],
    "cna_assigner": "VulnCheck",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86100.json"
}
References

Affected packages

Git / github.com/owen2345/camaleon-cms

Affected ranges

Type
GIT
Repo
https://github.com/owen2345/camaleon-cms
Events
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "2.7.5"
        },
        {
            "fixed": "2.9.2"
        }
    ]
}

Affected versions

2.*
2.7.5
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86100.json"