Authorization bypass through user-controlled key in Chamilo LMS - CVE-2026-32930

 

Authorization bypass through user-controlled key in Chamilo LMS - CVE-2026-32930

Published: April 24, 2026


Vulnerability identifier: #VU127563
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-32930
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to view and modify evaluation settings in other courses.

The vulnerability exists due to authorization bypass through a user-controlled key in public/main/gradebook/gradebook_edit_eval.php when processing the editeval GET parameter. A remote user can manipulate the editeval parameter to view and modify evaluation settings in other courses.

Evaluation IDs are sequential integers, which makes them easily enumerable.


Affected software

Chamilo LMS

How to mitigate CVE-2026-32930

Install security update from vendor's website.

Chamilo LMS - addressed in versions 1.11.38, 2.0.0 RC.3

External References

Related Security Bulletins