Missing Authorization in Chamilo LMS - CVE-2026-62305

 

Missing Authorization in Chamilo LMS - CVE-2026-62305

Published: August 4, 2026


Vulnerability identifier: #VU140895
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-62305
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to modify application data.

The vulnerability exists due to missing authorization in /template/document-templates/{documentId}/delete endpoint when handling delete requests for document templates. A remote attacker can send a crafted request to modify application data.

The issue can be exploited without authentication to delete document templates, modify template associations, and alter course content configuration.


Affected software

Chamilo LMS

How to mitigate CVE-2026-62305

Install security update from vendor's website.

Chamilo LMS - update to 2.0.3

External References