Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 6.2 PHP packages GHSA-g4c3-4g96-6g4m CVE-2026-45140 PKSA-m8ms-hgzz-8ddw

Chamilo LMS: Unauthenticated Remote Code Execution Vulnerability (CVE-2026-45140)

Chamilo LMS versions up to and including 2.0.0 contain a path traversal flaw that allows an unauthenticated remote attacker to execute arbitrary code on the server. The issue is fixed in version 2.0.1.

Synthesized by AI from 3 sources · updated 1 hour ago

AI summary

A critical vulnerability has been disclosed in Chamilo LMS, an open-source learning management system. The flaw, tracked as CVE-2026-45140, allows an unauthenticated remote attacker to execute arbitrary code on affected servers. It has been assigned a CVSS score of 9.8 (Critical). A fix is available in version 2.0.1.

What happened

A vulnerability in Chamilo LMS was publicly disclosed that allows an unauthenticated remote attacker to execute arbitrary code on the server running the affected software. The title published alongside the advisory references the 'CStudio upload flow,' but the authoritative advisory text itself does not specify the affected endpoint, component, input, or exploitation mechanism in detail.

Technical cause

The vulnerability is classified as CWE-22, Improper Limitation of a Pathname to a Restricted Directory (Path Traversal). This class of vulnerability typically allows an attacker to manipulate file paths to access or write files outside of an intended directory. In this case, the authoritative advisory does not provide further detail on the specific code path, parameter, or mechanism involved, so the exact exploitation technique cannot be confirmed from the available facts.

Why it matters

This vulnerability can be exploited by an unauthenticated attacker over the network, with no user interaction required, to achieve remote code execution. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) indicates low attack complexity and high impact to confidentiality, integrity, and availability. Successful exploitation could allow full compromise of the server hosting Chamilo LMS, including access to or modification of stored data.

Affected versions

Chamilo LMS versions from 0 up to and including 2.0.0 are affected, as reported by two independent advisory sources. Version 2.0.1 resolves this issue.

Fixes and mitigation

The vendor has released version 2.0.1 of Chamilo LMS, which fixes this vulnerability. No alternative mitigations are described in the available facts.

Recommended action

Site owners and administrators running Chamilo LMS version 2.0.0 or earlier should update to version 2.0.1 as soon as possible. Given the unauthenticated and remote nature of this vulnerability, treat this update as high priority.

PatchBriefing score

6.2 / 10 · Medium

Official CVSS: 9.8

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Why this score

This advisory carries a PatchBriefing score of 6.2, driven primarily by the CVSS base score of 9.8 (Critical), which contributes 5.39 points. Additional contributions come from the fact that the vulnerability can be exploited by an unauthenticated attacker over the network (+0.6) and requires no user interaction (+0.2). There is no evidence of known exploitation in the wild, no public exploit code, and no EPSS score is available, so these factors contribute 0 to the score. A fix is available, which also means the 'no fix available' penalty does not apply.

Affected versions

chamilo/chamilo-lms <= 2.0.0
vulnerable
chamilo/chamilo-lms <=2.0.0
vulnerable
≥ 2.0.1
patched

Reported fixes

The vendor has released version 2.0.1 of Chamilo LMS, which fixes this vulnerability. No alternative mitigations are described in the available facts.

How this was built

3 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • Packagist Security Advisories registry
  • NVD (NIST) database
Unified report
Chamilo LMS: Unauthenticated Remote Code Execution Vulnerability (CVE-2026-45140)
1 article · 3 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email