Server-Side Template Injection in CamaleonCMS by CamaleonCMS
CVE-2026-73330

7.5HIGH

Key Information:

Vendor

Owen2345

Vendor
CVE Published:
12 August 2026

What is CVE-2026-73330?

CamaleonCMS version 2.9.1 contains a critical vulnerability that exposes authenticated administrators to server-side template injection. By manipulating the email parameter during the test_email settings action, attackers can inject ERB tags that allow arbitrary command execution when processed by the Rails inline template renderer. This flaw enables attackers to execute harmful Ruby code as the user running the Rails process, significantly compromising the application's security.

Affected Version(s)

CamaleonCMS 0 <= 2.9.1

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Amir Aliu & Enrik Mustafa
.