Missing Authorization in Chamilo LMS - CVE-2026-62306

 

Missing Authorization in Chamilo LMS - CVE-2026-62306

Published: August 4, 2026


Vulnerability identifier: #VU140893
CSH Severity: Medium
CVSS v4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-62306
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to modify application data.

The vulnerability exists due to missing authorization in the /template/document-templates/create endpoint when handling template creation and document modification requests. A remote attacker can send a crafted request to modify application data.

The issue can be exploited to create document templates, alter template associations, and mark arbitrary documents as templates.


Affected software

Chamilo LMS

How to mitigate CVE-2026-62306

Install security update from vendor's website.

Chamilo LMS - update to 2.0.3

External References