Improperly Controlled Modification of Dynamically-Determined Object Attributes in Chamilo LMS - CVE-2026-61785

 

Improperly Controlled Modification of Dynamically-Determined Object Attributes in Chamilo LMS - CVE-2026-61785

Published: August 4, 2026


Vulnerability identifier: #VU140902
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-61785
CWE-ID: CWE-915
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improperly controlled modification of dynamically-determined object attributes in registration.php and UserManager::create_user() when processing self-registration requests. A remote attacker can submit a crafted status field during registration to escalate privileges.

User interaction is required to complete registration, and the issue can assign the session administrator or HR role instead of the intended student or teacher role.


Affected software

Chamilo LMS

How to mitigate CVE-2026-61785

Install security update from vendor's website.

Chamilo LMS - addressed in versions 1.11.40, 2.0.3

External References