CVE-2026-66748

Source
https://cve.org/CVERecord?id=CVE-2026-66748
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-66748.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-66748
Published
2026-07-28T15:19:52.609Z
Modified
2026-07-30T04:02:24.431533165Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Camaleon CMS 2.1.1 - 2.9.1 Authenticated RCE via select_eval Custom Field
Details

Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with customfields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the selecteval custom field type. Attackers can store an attacker-controlled Ruby expression in the field options command parameter, which is evaluated via instance_eval within an ERB view whenever a post edit page is rendered, achieving server-side code execution with web server process privileges.

Database specific
{
    "cna_assigner": "VulnCheck",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/66xxx/CVE-2026-66748.json",
    "cwe_ids": [
        "CWE-94"
    ]
}
References

Affected packages

Git / github.com/owen2345/camaleon-cms

Affected ranges

Type
GIT
Repo
https://github.com/owen2345/camaleon-cms
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "2.1.1"
        },
        {
            "fixed": "2.9.1"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

2.*
2.1.1
2.1.2
2.1.2.0
2.2.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.4.0
2.4.1
2.4.2
2.4.3
2.4.3.10
2.4.3.11
2.4.3.12
2.4.3.7
2.4.4
2.4.4.2
2.4.4.3
2.4.4.5
2.4.4.6
2.4.5
2.4.5.1
2.4.5.10
2.4.5.11
2.4.5.12
2.4.5.13
2.4.5.14
2.4.5.7
2.4.6.0
2.4.6.1
2.4.6.7
2.5.1
2.5.3
2.5.3.1
2.6.0
2.6.0.1
2.6.1
2.6.2
2.6.4
2.7.0
2.7.1
2.7.3
2.7.4
2.7.5
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.1
2.9.2
camaleon_cms-2.*
camaleon_cms-2.4.5.11.gem
v2.*
v2.1.1.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-66748.json"