{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/camaleoncms/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-56721"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CamaleonCMS"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["CamaleonCMS"],"content_html":"\u003cp\u003eCamaleonCMS versions 2.9.2 and earlier contain a critical privilege escalation vulnerability (CVE-2026-56721) stemming from an Insecure Direct Object Reference (IDOR) flaw within the UsersController. The vulnerability resides in a parameter confusion discrepancy between the authorization filter, which checks the 'id' parameter, and the action body, which processes the 'user_id' parameter. An authenticated low-privileged attacker can exploit this by crafting a PATCH request to the 'update_ajax' endpoint. By setting the 'id' parameter to their own identifier to satisfy the authorization filter, and concurrently setting the 'user_id' parameter to an administrator or target user's identifier, the application logic incorrectly loads and mutates the victim's account. Successful exploitation allows for the modification of any user's credentials, facilitating a full site takeover. Defenders should prioritize patching or implementing request validation logic to ensure parameter consistency.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains authenticated access to the target application with a low-privileged account.\u003c/li\u003e\n\u003cli\u003eAttacker discovers the 'update_ajax' PATCH endpoint used for user profile management.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP PATCH request targeting the '/update_ajax' route.\u003c/li\u003e\n\u003cli\u003eAttacker includes their own user ID in the 'id' parameter to bypass the authorization filter.\u003c/li\u003e\n\u003cli\u003eAttacker includes the victim's (e.g., admin) user ID in the 'user_id' parameter within the request body.\u003c/li\u003e\n\u003cli\u003eThe application performs the authorization check against the attacker's ID, which succeeds.\u003c/li\u003e\n\u003cli\u003eThe application processes the request body, using the victim's ID to perform the update.\u003c/li\u003e\n\u003cli\u003eThe victim's password or other sensitive account information is overwritten by the attacker, achieving account takeover.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-56721 allows an unprivileged attacker to escalate privileges to administrator status. This grants the attacker full control over the CamaleonCMS instance, potentially leading to unauthorized data exfiltration, system configuration changes, or the deployment of additional malicious persistence mechanisms. The impact is significant for organizations relying on CamaleonCMS for content management, as it provides a direct path to site-wide administrative compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate CamaleonCMS to the latest patched version immediately to remediate CVE-2026-56721.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to web server logs to monitor for unauthorized 'update_ajax' PATCH requests with mismatched 'id' and 'user_id' parameter combinations.\u003c/li\u003e\n\u003cli\u003eReview web application access logs for repeated PATCH requests to 'update_ajax' originating from non-administrative accounts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-11T18:36:28Z","date_published":"2026-08-11T18:36:28Z","id":"https://feed.craftedsignal.io/briefs/2026-08-camaleoncms-idor/","summary":"CamaleonCMS versions 2.9.2 and earlier are vulnerable to privilege escalation via an IDOR parameter confusion flaw in the UsersController, allowing authenticated attackers to overwrite arbitrary user credentials.","title":"Privilege Escalation via IDOR in CamaleonCMS","url":"https://feed.craftedsignal.io/briefs/2026-08-camaleoncms-idor/"}],"language":"en","title":"CraftedSignal Threat Feed - CamaleonCMS","version":"https://jsonfeed.org/version/1.1"}