Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 04 Sep 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect targets when fetching remote files in the Upload from URL media feature. Authenticated attackers can supply URLs that pass initial validation but redirect to internal network addresses, allowing server-side request forgery to internal services. | |
| Title | Camaleon CMS 2.7.5 through 2.9.1 SSRF via HTTP Redirect in Upload from URL | |
| First Time appeared |
Tuzitio
Tuzitio camaleon Cms |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:tuzitio:camaleon_cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tuzitio
Tuzitio camaleon Cms |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-04T23:16:23.223Z
Reserved: 2026-09-04T22:51:22.722Z
Link: CVE-2026-86100
No data.
Status : Received
Published: 2026-09-05T00:17:20.810
Modified: 2026-09-05T00:17:20.810
Link: CVE-2026-86100
No data.
OpenCVE Enrichment
Updated: 2026-09-05T00:30:18Z