{"id":"CVE-2026-1776","details":"Camaleon CMS versions 2.4.5.0 through 2.9.0, prior to commit f54a77e, contain a path traversal vulnerability in the AWS S3 uploader implementation that allows authenticated users to read arbitrary files from the web server’s filesystem. The issue occurs in the download_private_file functionality when the application is configured to use the CamaleonCmsAwsUploader backend. Unlike the local uploader implementation, the AWS uploader does not validate file paths with valid_folder_path?, allowing directory traversal sequences to be supplied via the file parameter. As a result, any authenticated user, including low-privileged registered users, can access sensitive files such as /etc/passwd. This issue represents a bypass of the incomplete fix for CVE-2024-46987 and affects deployments using the AWS S3 storage backend.","aliases":["GHSA-jw5g-f64p-6x78"],"modified":"2026-04-10T05:38:08.271688Z","published":"2026-03-10T07:38:01.950Z","references":[{"type":"WEB","url":"https://camaleon.website/"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/camaleon-cms-aws-uploader-authenticated-path-traversal-arbitrary-file-read"},{"type":"FIX","url":"https://github.com/owen2345/camaleon-cms/commit/f54a77e2a7be601215ea1b396038c589a0cab9af"},{"type":"FIX","url":"https://github.com/owen2345/camaleon-cms/pull/1127"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/owen2345/camaleon-cms","events":[{"introduced":"0"},{"last_affected":"c3292fef7a84543a65584cab654a39b25bc7f523"},{"fixed":"f54a77e2a7be601215ea1b396038c589a0cab9af"}],"database_specific":{"versions":[{"introduced":"2.4.5.0"},{"last_affected":"2.9.0"}]}}],"versions":["0.1.7","0.2.0","2.1.1","2.1.2","2.1.2.0","2.2.0","2.3.1","2.3.2","2.3.3","2.3.4","2.3.5","2.3.6","2.3.7","2.4.0","2.4.1","2.4.2","2.4.3","2.4.3.10","2.4.3.11","2.4.3.12","2.4.3.7","2.4.4","2.4.4.2","2.4.4.3","2.4.4.5","2.4.4.6","2.4.5","2.4.5.1","2.4.5.10","2.4.5.11","2.4.5.12","2.4.5.13","2.4.5.14","2.4.5.7","2.4.6.0","2.4.6.1","2.4.6.7","2.5.1","2.5.3","2.5.3.1","2.6.0","2.6.0.1","2.6.1","2.6.2","2.6.4","2.7.0","2.7.1","2.7.3","2.7.4","2.7.5","2.8.0","2.8.1","2.8.2","2.8.3","2.9.0","2.9.1","camaleon_cms-2.4.5.11.gem","v2.0.0","v2.1.1.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-1776.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}]}