{"id":"CVE-2026-1776","summary":"Camaleon CMS AWS Uploader Authenticated Path Traversal Arbitrary File Read","details":"Camaleon CMS versions 2.4.5.0 through 2.9.0, prior to commit f54a77e, contain a path traversal vulnerability in the AWS S3 uploader implementation that allows authenticated users to read arbitrary files from the web server’s filesystem. The issue occurs in the download_private_file functionality when the application is configured to use the CamaleonCmsAwsUploader backend. Unlike the local uploader implementation, the AWS uploader does not validate file paths with valid_folder_path?, allowing directory traversal sequences to be supplied via the file parameter. As a result, any authenticated user, including low-privileged registered users, can access sensitive files such as /etc/passwd. This issue represents a bypass of the incomplete fix for CVE-2024-46987 and affects deployments using the AWS S3 storage backend.","aliases":["GHSA-jw5g-f64p-6x78"],"modified":"2026-08-12T03:51:20.701675107Z","published":"2026-03-09T21:08:06.600Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-22"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/1xxx/CVE-2026-1776.json"},"references":[{"type":"WEB","url":"https://camaleon.website/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/1xxx/CVE-2026-1776.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-1776"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/camaleon-cms-aws-uploader-authenticated-path-traversal-arbitrary-file-read"},{"type":"REPORT","url":"https://github.com/owen2345/camaleon-cms/pull/1127"},{"type":"FIX","url":"https://github.com/owen2345/camaleon-cms/commit/f54a77e2a7be601215ea1b396038c589a0cab9af"},{"type":"PACKAGE","url":"https://github.com/owen2345/camaleon-cms"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/owen2345/camaleon-cms","events":[{"introduced":"29faf0a01d37a9fac1e7d64ed51b1d324739fcaa"},{"fixed":"f54a77e2a7be601215ea1b396038c589a0cab9af"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:tuzitio:camaleon_cms:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.4.5"},{"last_affected":"2.9.0"}]}}],"versions":["2.9.1","2.9.0","2.8.3","2.8.2","2.8.1","2.8.0","2.7.5","2.7.4","2.7.3","2.7.1","2.7.0","2.6.4","2.6.2","2.6.1","2.6.0.1","2.6.0","2.5.3.1","2.5.3","2.5.1","2.4.6.7","2.4.6.1","2.4.6.0","2.4.5.14","2.4.5.13","2.4.5.12","camaleon_cms-2.4.5.11.gem","2.4.5.11","2.4.5.10","2.4.5.7","2.4.5.1","2.4.5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-1776.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}