Server-Side Template Injection in CamaleonCMS by CamaleonCMS
CVE-2026-73330
7.5HIGH
What is CVE-2026-73330?
CamaleonCMS version 2.9.1 contains a critical vulnerability that exposes authenticated administrators to server-side template injection. By manipulating the email parameter during the test_email settings action, attackers can inject ERB tags that allow arbitrary command execution when processed by the Rails inline template renderer. This flaw enables attackers to execute harmful Ruby code as the user running the Rails process, significantly compromising the application's security.
Affected Version(s)
CamaleonCMS 0 <= 2.9.1
