Improper privilege management in Chamilo LMS - CVE-2026-61786
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper privilege management in the switch_user feature when processing a crafted impersonation request. A remote attacker can send a specially crafted request to escalate privileges.
The issue allows impersonation of any account, including a global administrator, because no restriction is enforced on the target user's privilege.