Authorization bypass through user-controlled key in Chamilo LMS - CVE-2026-33703

 

Authorization bypass through user-controlled key in Chamilo LMS - CVE-2026-33703

Published: April 24, 2026


Vulnerability identifier: #VU127559
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33703
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in the /social-network/personal-data/{userId} endpoint when handling requests with a modified userId parameter. A remote user can send a crafted request with an arbitrary userId to disclose sensitive information.

The issue exposes personal data and API tokens of arbitrary users, including administrator accounts.


Affected software

Chamilo LMS

How to mitigate CVE-2026-33703

Install security update from vendor's website.

Chamilo LMS - update to 2.0.0 RC.3

External References

Related Security Bulletins