CVE-2026-33185: Groups Controller Rb Cwe 000 Cve 2026 33185

Found weak authorization check `ensure_can_edit!` in `test_email_settings`. This allows non-staff group owners to trigger an SSRF.

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0Ruby
greprules fetch cve-2026-33185-groups-controller-rb-cwe-000-cve-2026-33185 --engine opengrep

Description

Found weak authorization check `ensure_can_edit!` in `test_email_settings`. This allows non-staff group owners to trigger an SSRF.