{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/camaleon-cms/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-66748"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Camaleon CMS (2.1.1 through 2.9.1)"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","cms","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Camaleon CMS"],"content_html":"\u003cp\u003eCVE-2026-66748 details an authenticated remote code execution vulnerability affecting Camaleon CMS versions 2.1.1 through 2.9.1. An attacker with specific administrative permissions, namely \u0026quot;custom_fields manage,\u0026quot; can leverage this flaw to execute arbitrary Ruby code on the compromised server. This is achieved by injecting a crafted Ruby expression into the \u0026quot;options command\u0026quot; parameter of a \u003ccode\u003eselect_eval\u003c/code\u003e custom field type. When a user subsequently renders a post edit page that incorporates this malicious custom field, the embedded Ruby code is evaluated using \u003ccode\u003einstance_eval\u003c/code\u003e within an ERB view, resulting in server-side code execution under the privileges of the web server process. This vulnerability poses a significant risk to the confidentiality, integrity, and availability of the affected CMS instances.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker obtains authentication credentials for Camaleon CMS with sufficient privileges, including the \u003ccode\u003ecustom_fields manage\u003c/code\u003e permission.\u003c/li\u003e\n\u003cli\u003eThe attacker navigates to the custom field configuration interface within the Camaleon CMS administration panel.\u003c/li\u003e\n\u003cli\u003eThe attacker creates a new \u003ccode\u003eselect_eval\u003c/code\u003e custom field or modifies an existing one.\u003c/li\u003e\n\u003cli\u003eWithin the configuration for the \u003ccode\u003eselect_eval\u003c/code\u003e custom field, the attacker injects a malicious Ruby expression into the \u003ccode\u003eoptions command\u003c/code\u003e parameter.\u003c/li\u003e\n\u003cli\u003eThe Camaleon CMS backend persists this malicious Ruby expression within its database.\u003c/li\u003e\n\u003cli\u003eSubsequently, an authorized user (potentially the attacker) renders a post edit page that is configured to display or utilize the specially crafted custom field.\u003c/li\u003e\n\u003cli\u003eDuring the server-side rendering of the ERB view for the post edit page, the \u003ccode\u003einstance_eval\u003c/code\u003e function processes the stored malicious Ruby expression.\u003c/li\u003e\n\u003cli\u003eThe injected arbitrary Ruby code executes on the Camaleon CMS server with the privileges of the web server process, achieving remote code execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-66748 grants an authenticated attacker full remote code execution capabilities on the Camaleon CMS server. This can lead to complete compromise of the CMS instance, allowing for data theft, modification, or deletion, as well as the potential to establish persistent access or pivot to other systems within the network. The high CVSS v3.1 Base Score of 8.8 reflects the critical nature of this vulnerability, indicating significant impact on confidentiality, integrity, and availability of the affected system and potentially associated data.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch Camaleon CMS installations immediately to a version beyond 2.9.1 to address CVE-2026-66748.\u003c/li\u003e\n\u003cli\u003eReview user permissions and enforce the principle of least privilege, especially for users with \u003ccode\u003ecustom_fields manage\u003c/code\u003e permissions, to mitigate the risk posed by CVE-2026-66748.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for unusual activity following successful authentication, specifically looking for attempts to modify custom field configurations or access \u003ccode\u003eselect_eval\u003c/code\u003e fields with unusual parameters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T16:21:16Z","date_published":"2026-07-28T16:21:16Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-66748-rce/","summary":"Camaleon CMS versions 2.1.1 through 2.9.1 are vulnerable to authenticated remote code execution where an attacker with `custom_fields manage` permission can execute arbitrary Ruby code by injecting a malicious expression into the `select_eval` custom field type's options command parameter, which is then evaluated via `instance_eval` within an ERB view when a post edit page is rendered, leading to server-side code execution with web server process privileges.","title":"Authenticated Remote Code Execution in Camaleon CMS","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-66748-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Camaleon CMS","version":"https://jsonfeed.org/version/1.1"}