Authenticated Remote Code Execution Vulnerability in Chamilo LMS
CVE-2026-34239

7.5HIGH

Key Information:

Vendor

Chamilo

Vendor
CVE Published:
20 July 2026

What is CVE-2026-34239?

Chamilo LMS versions 1.11.40 and prior have a significant vulnerability allowing authenticated users to execute arbitrary code remotely through the main/inc/ajax/lang.ajax.php file. This endpoint relies solely on the 'api_protect_course_script(true)' function for protection, enabling any user who is enrolled in a course, such as students and teachers, to exploit this flaw. It is crucial for users and administrators to assess their systems and apply necessary updates to mitigate this risk.

Affected Version(s)

chamilo-lms <= 1.11.40

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.