PT-2026-32021 · Unknown · Chamilo Lms

CVE-2026-33706

·

Published

2026-04-10

·

Updated

2026-04-10

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Chamilo LMS versions prior to 1.11.38
Description Chamilo LMS is a learning management system. Authenticated users with a REST API key can modify their own status field via the update user from username API endpoint. A student (status=5) can change their status to Teacher/CourseManager (status=1), gaining course creation and management privileges.
Recommendations Update to version 1.11.38 or later.

Exploit

Fix

DoS

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33706
GHSA-3GQC-XR75-PCPW

Affected Products

Chamilo Lms