Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-102261 — Non-destructive Go verifier that checks whether a Camaleon CMS instance applies the authorization fix for CVE-2026-102261 in the media crop endpoint. | Kitploit
Tools/GitHubGitHub/7acini/cve-2026-102261
Authentication & AuthorizationDefensive ToolsVulnerability ScannersWeb Vulnerability ScannersVulnerability AnalysisSecurity VirtualizationWeb SecurityPenetration Testing
GitHub7acini/cve-2026-102261

CVE-2026-102261

Non-destructive Go verifier that checks whether a Camaleon CMS instance applies the authorization fix for CVE-2026-102261 in the media crop endpoint.

54 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

CVE-2026-102261

This project contains a non-destructive checker to confirm whether an authorized instance of Camaleon CMS enforces the authorization introduced in version 2.9.3.

Scope

The issue affects POST /admin/media/crop in Camaleon CMS up to 2.9.2. A user with :manage, :media, but without :manage, :users, could supply another user's ID in saved_avatar and achieve an avatar write outside their authorized object. The fix requires :manage, :users for any target other than the user themselves.

The checker sends a single authenticated POST with:

  • a saved_avatar from a disposable account different from the authenticated account;
  • a deliberately nonexistent cp_img_path.

In the fixed version, authorization occurs before any file processing and the application responds with a redirect (typically 302). In an older version, the request is not denied at that stage and the result is only INCONCLUSIVE: this program does not send an image, does not read data, and does not attempt to modify any avatar.

Usage (authorized lab only)

Create two test accounts on the same site:

  1. one with :manage, :media, but without :manage, :users;
  2. another disposable account whose ID will be used as the target.

Obtain the session cookie of the first account and run:

go test ./...
go run . \
  --i-own-this-lab \
  --url http://127.0.0.1:3000 \
  --cookie '_session_id=COLOQUE_A_SESSAO_DE_TESTE_AQUI' \
  --nonself-user-id 42

PROTECTED means the endpoint denied the operation before processing the image path. INCONCLUSIVE calls for validating the installed version and updating; it is not confirmation of exploitation.

Fix

Update to Camaleon CMS 2.9.3 or later. The patch is c143e145caa600947e70a240e87f2fed889149d3.

References

  • CVE-2026-102261 on VulDB
  • Release 2.9.3
Download Tool