CVE-2026-45140
9.8Chamilo · Chamilo LMS
Chamilo LMS versions prior to 2.0.1 are susceptible to unauthenticated remote code execution, potentially allowing a full system compromise.
Executive summary
A critical vulnerability in Chamilo LMS allows unauthenticated remote attackers to execute arbitrary code, posing a severe risk to server integrity and data confidentiality.
Vulnerability
This vulnerability involves improper control of code generation and potential path traversal, which enables an unauthenticated remote attacker to achieve arbitrary code execution on the underlying server.
Business impact
The CVSS score of 9.8 reflects the critical nature of this flaw, as it requires no authentication and allows for complete system compromise. A successful exploit could lead to full unauthorized access to the learning management system, potential exfiltration of sensitive student or faculty data, and total loss of server availability.
Remediation
Immediate Action: Upgrade Chamilo LMS to version 2.0.1 or later immediately to apply the vendor-provided security patch.
Proactive Monitoring: Review web server and application access logs for unusual request patterns, specifically looking for attempts to access non-public directories or execute unauthorized scripts.
Compensating Controls: Implement a Web Application Firewall (WAF) to filter malicious traffic and block common code injection or path traversal patterns targeting the LMS infrastructure.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical CVSS severity and the potential for unauthenticated remote code execution, organizations running Chamilo LMS must prioritize the transition to version 2.0.1. Failure to patch this vulnerability leaves the application and its host server exposed to total compromise by remote actors.
More Chamilo CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section