Use of insufficiently random values in Chamilo LMS - CVE-2026-33710
Published: April 24, 2026
Chamilo LMS
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to use of insufficiently random values in REST API key generation in main/inc/lib/usermanager.lib.php when generating API keys. A remote attacker can brute-force a predictable API key to disclose sensitive information.
Exploitation requires knowledge of a username and an approximate API key creation time.