


Perceptive Security
SOC/SIEM Consultancy

Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission t…
Published:
28 July 2026 at 00:00:00
Alert date:
28 July 2026 at 19:04:58
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities
Camaleon CMS versions 2.1.1 through 2.9.1 are affected by an authenticated remote code execution vulnerability tracked as CVE-2026-66748. Users with the custom_fields manage permission can exploit the select_eval custom field type to inject and execute arbitrary Ruby code. The malicious expression is stored in the field options command parameter and evaluated via instance_eval within an ERB view when a post edit page is rendered. This results in server-side code execution running with web server process privileges. The vulnerability requires authentication but can be triggered by lower-privileged users with specific permissions. A fix has been released in version 2.9.2. Proof-of-concept code and a GitHub pull request addressing the issue are publicly available, raising the risk of exploitation.
Technical details
Mitigation steps:
Affected products:
Camaleon CMS 2.1.1
Camaleon CMS 2.9.1
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-66748
https://github.com/owen2345/camaleon-cms/commit/158823668e2e5c3114a69b34cf1c96cb41533c5f
https://github.com/owen2345/camaleon-cms/pull/1136
https://github.com/owen2345/camaleon-cms/releases/tag/2.9.2
https://github.com/theopaid/Camaleon-CMS---Authenticated-RCE-via-select_eval-Custom-Field
https://www.vulncheck.com/advisories/camaleon-cms-authenticated-rce-via-select-eval-custom-field
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
