Executive brief
Camaleon CMS, a content management system built on Ruby on Rails, contains a security flaw that allows authorized users with specific permissions to execute malicious code on the server. By exploiting a specific custom field type, an attacker can run commands with the same privileges as the web server, potentially leading to a full system takeover or theft of sensitive data. This vulnerability requires the attacker to have an account with permissions to manage custom fields.
Technical details
An authenticated remote code execution (RCE) vulnerability exists in Camaleon CMS (v2.1.1-2.9.1) due to improper input validation in the 'select_eval' custom field type. Users with 'custom_fields' management permissions can inject arbitrary Ruby expressions into the 'field options command' parameter. This input is subsequently executed via 'instance_eval' within an ERB view when a post edit page is rendered. An attacker can leverage this to achieve server-side code execution with the privileges of the web server process. The issue is addressed in version 2.9.2 by introducing granular permissions for 'select_eval' and restricting its use to authorized administrators.
Affected products
- owen2345 Camaleon CMS 2.1.1 - 2.9.1
Timeline
- 2026-03-29: disclosed: Initial fix development started via pull request
- 2026-05-01: patched: Version 2.9.2 released with security fixes
- 2026-07-28: advisory: CVE-2026-66748 published
References
- https://github.com/owen2345/camaleon-cms/commit/158823668e2e5c3114a69b34cf1c96cb41533c5f
- https://github.com/owen2345/camaleon-cms/pull/1136
- https://github.com/owen2345/camaleon-cms/releases/tag/2.9.2
- https://github.com/theopaid/Camaleon-CMS---Authenticated-RCE-via-select_eval-Custom-Field
- https://www.vulncheck.com/advisories/camaleon-cms-authenticated-rce-via-select-eval-custom-field