Back

CRITICAL

Chamilo LMS affected by unauthenticated RCE in main/install folder

Published Apr 10, 2026

Description

Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise-blocked PHP code from the main/install/ directory and allow an unauthenticated attacker to modify existing files or create new files where allowed by system permissions. This only affects portals with the main/install/ directory still present and read-accessible. This vulnerability is fixed in 1.11.38.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Apr 10, 2026
Updated Apr 15, 2026
Reserved Mar 23, 2026
CISA Vulnrichment
Updated Apr 15, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published Apr 10, 2026
Updated Apr 15, 2026
Exploited since n/a
EUVD-2026-21539