Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect targets when fetching remote files in the Upload from URL media feature. Authenticated attackers can supply URLs that pass initial validation but redirect to internal network addresses, allowing server-side request forgery to internal services.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 04 Sep 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect targets when fetching remote files in the Upload from URL media feature. Authenticated attackers can supply URLs that pass initial validation but redirect to internal network addresses, allowing server-side request forgery to internal services. | |
| Title | Camaleon CMS 2.7.5 through 2.9.1 SSRF via HTTP Redirect in Upload from URL | |
| First Time appeared |
Tuzitio
Tuzitio camaleon Cms |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:tuzitio:camaleon_cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tuzitio
Tuzitio camaleon Cms |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-04T23:16:23.223Z
Reserved: 2026-09-04T22:51:22.722Z
Link: CVE-2026-86100
No data.
Status : Received
Published: 2026-09-05T00:17:20.810
Modified: 2026-09-05T00:17:20.810
Link: CVE-2026-86100
No data.
OpenCVE Enrichment
Updated: 2026-09-05T00:30:18Z
Weaknesses