Missing Authorization in Chamilo LMS - CVE-2026-33708

 

Missing Authorization in Chamilo LMS - CVE-2026-33708

Published: April 24, 2026


Vulnerability identifier: #VU127548
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33708
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to missing authorization in the get_user_info_from_username REST API endpoint when handling authenticated requests for user information by username. A remote user can send a crafted API request with a target username to disclose sensitive information.

The endpoint returns email address, first name, last name, user ID, username, and active status for arbitrary users.


Affected software

Chamilo LMS

How to mitigate CVE-2026-33708

Install security update from vendor's website.

Chamilo LMS - update to 1.11.38

External References

Related Security Bulletins