PT-2026-32939 · Unknown · Chamilo Lms

·

CVE-2026-40291

·

Published

2026-04-14

·

Updated

2026-04-15

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chamilo LMS versions prior to 2.0.0-RC.3
Description An insecure direct object modification in the 'PUT /api/users/{id}' endpoint allows authenticated users with the ROLE STUDENT role to escalate their privileges to ROLE ADMIN. This occurs because the security expression is granted('EDIT', object) only verifies record ownership, while the roles field remains in the writable serialization group. By modifying the roles field on their own user record, an attacker can gain full administrative control of the platform, including access to all courses, user data, grades, and administrative settings.
Recommendations Update to version 2.0.0-RC.3.

Exploit

Fix

DoS

Incorrect Authorization

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40291
GHSA-7PHX-W897-4C9X

Affected Products

Chamilo Lms