Missing Authorization in Chamilo LMS - CVE-2026-62304

 

Missing Authorization in Chamilo LMS - CVE-2026-62304

Published: August 4, 2026


Vulnerability identifier: #VU140897
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-62304
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to missing authorization in the /template/all-templates/{courseId} endpoint when handling requests for course template data. A remote attacker can send a request for an arbitrary course ID to disclose sensitive information.

The issue can expose template metadata and template content from private courses without authentication.


Affected software

Chamilo LMS

How to mitigate CVE-2026-62304

Install security update from vendor's website.

Chamilo LMS - update to 2.0.3

External References