Improper privilege management in Chamilo LMS - CVE-2026-33706
Published: April 24, 2026
Chamilo LMS
Detailed vulnerability description
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper privilege management in the update_user_from_username endpoint when handling REST API requests to modify a user's own profile. A remote user can modify the status field to escalate privileges.
Exploitation requires a valid REST API key.