User Enumeration Vulnerability in Chamilo LMS Affects All Authenticated Users
CVE-2026-33736
6.5MEDIUM
What is CVE-2026-33736?
Chamilo LMS, a widely-used learning management system, is susceptible to a user enumeration vulnerability that allows any authenticated user, including those with student roles, to access personal information of other users. This includes sensitive details like email addresses, phone numbers, and user roles through the API endpoint /api/users. The issue, which can lead to privacy violations and unauthorized insights into user data, has been addressed in the release 2.0.0-RC.3.
Affected Version(s)
chamilo-lms >= 2.0.0-alpha.1, < 2.0.0-RC.3
