Authorization bypass through user-controlled key in Chamilo LMS - CVE-2026-62307

 

Authorization bypass through user-controlled key in Chamilo LMS - CVE-2026-62307

Published: August 4, 2026


Vulnerability identifier: #VU140892
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-62307
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information and copy private course resources.

The vulnerability exists due to authorization bypass through a user-controlled key in the Course Maintenance copy endpoints when handling a user-supplied sourceCourseId. A remote user can supply an arbitrary course code as the source course identifier to disclose sensitive information and copy private course resources.

Exploitation requires access to any destination course.


Affected software

Chamilo LMS

How to mitigate CVE-2026-62307

Install security update from vendor's website.

Chamilo LMS - update to 2.0.3

External References