Authorization bypass through user-controlled key in Chamilo LMS - CVE-2026-33703
Published: April 24, 2026
Chamilo LMS
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the /social-network/personal-data/{userId} endpoint when handling requests with a modified userId parameter. A remote user can send a crafted request with an arbitrary userId to disclose sensitive information.
The issue exposes personal data and API tokens of arbitrary users, including administrator accounts.