What is CVE-2026-66748?
This critical vulnerability (CVE-2026-66748) affects Camaleon CMS versions 2.1.1 through 2.9.1, allowing authenticated users with `custom_fields` manage permission to execute arbitrary Ruby code via a malicious expression in the `select_eval` custom field type. Immediate update to the latest version and review of privileged accounts are strongly recommended.
Azərbaycanca: Bu kritik zəiflik (CVE-2026-66748) Camaleon CMS-in 2.1.1-dən 2.9.1-ə qədər olan versiyalarına təsir edir və autentifikasiya olunmuş istifadəçilərə `select_eval` xüsusi sahə növü vasitəsilə zərərli Ruby kodu icra etməyə imkan verir. Yalnız `custom_fields` idarəetmə icazəsi olan istifadəçilər bundan istifadə edə bilər, ona görə də sistem dərhal ən son versiyaya yenilənməli və bu icazəyə malik hesablar yoxlanılmalıdır.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which versions of Camaleon CMS are affected by CVE-2026-66748?
This critical vulnerability affects Camaleon CMS versions 2.1.1 through 2.9.1.
What permission does an attacker need to exploit CVE-2026-66748?
The attacker must be an authenticated user with `custom_fields` manage permission.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.