CVE-2026-1776 | owen2345 Camaleon CMS up to 2.9.0 CamaleonCmsAwsUploader download_private_file File path traversal (f54a77e)
A vulnerability labeled as critical has been found in owen2345 Camaleon CMS up to 2.9.0. The impacted element is the function download_private_file of the component CamaleonCmsAwsUploader. The manipulation of the argument File results in path traversal.
This vulnerability is cataloged as CVE-2026-1776. The attack may be launched remotely. There is no exploit available.
It is advisable to implement a patch to correct this issue.