Improper access control in Chamilo LMS - CVE-2026-33698
Published: April 24, 2026
Chamilo LMS
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper access control in the main/install directory when accessing otherwise-blocked PHP code. A remote attacker can enable PHP code in that directory and modify existing files or create new files to execute arbitrary code.
Only portals with the main/install/ directory still present and readable are vulnerable.