Authenticated Remote Code Execution Vulnerability in Chamilo LMS
CVE-2026-34239
7.5HIGH
What is CVE-2026-34239?
Chamilo LMS versions 1.11.40 and prior have a significant vulnerability allowing authenticated users to execute arbitrary code remotely through the main/inc/ajax/lang.ajax.php file. This endpoint relies solely on the 'api_protect_course_script(true)' function for protection, enabling any user who is enrolled in a course, such as students and teachers, to exploit this flaw. It is crucial for users and administrators to assess their systems and apply necessary updates to mitigate this risk.
Affected Version(s)
chamilo-lms <= 1.11.40
