PT-2026-95083 · Unknown · Chamilo Lms

·

CVE-2026-45140

·

Published

2026-09-17

·

Updated

2026-09-19

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chamilo LMS versions prior to 2.0.1
Description Chamilo LMS, an open-source learning management system, contains a flaw that allows an unauthenticated remote attacker to execute arbitrary code directly on the server. The authoritative advisory does not identify the specific affected endpoint, component, input, or exploitation mechanism.
Recommendations Update Chamilo LMS to version 2.0.1. Restrict access to the LMS interface to trusted internal networks or require VPN authentication. Review web server access logs for unusual POST requests or script execution attempts in uploads/plugins directories.

Exploit

Fix

RCE

Path traversal

Code Injection

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45140
GHSA-G4C3-4G96-6G4M

Affected Products

Chamilo Lms