A vulnerability categorized as critical has been discovered in owen2345 CamaleonCMS up to 2.9.2. Affected is the function updated_ajax of the file app/controllers/users_controller.rb of the component Authorization Filter. The manipulation of the argument id/user_id results in authorization bypass.

This vulnerability is known as CVE-2026-56721. It is possible to launch the attack remotely. No exploit is available.