CVE-2026-66748 | theopaid Camaleon CMS up to 2.9.1 select_eval instance_eval command permission
A vulnerability marked as problematic has been reported in theopaid Camaleon CMS up to 2.9.1. Impacted is the function instance_eval of the component select_eval. This manipulation of the argument command causes permission issues.
This vulnerability is registered as CVE-2026-66748. Remote exploitation of the attack is possible. No exploit is available.