CPE
Authenticated attackers with subscriber-level access can achieve remote code execution in ACPT (Premium) versions up to 2.0.66 by injecting malicious Twig expressions via the REST API.