Incorrect authorization in Chamilo LMS - CVE-2026-54748

 

Incorrect authorization in Chamilo LMS - CVE-2026-54748

Published: August 4, 2026


Vulnerability identifier: #VU140921
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-54748
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify course tool-introduction content and execute arbitrary script in other users' browsers.

The vulnerability exists due to improper authorization in the ResourceVoter for AbstractResource-gated entities when handling API Platform endpoints and legacy access checks. A remote user can access and modify CToolIntro objects outside their authorized scope to modify course tool-introduction content and execute arbitrary script in other users' browsers.

The issue can affect resources protected only by this voter, and exploitation can cross tenant and course boundaries.


Affected software

Chamilo LMS

How to mitigate CVE-2026-54748

Install security update from vendor's website.

Chamilo LMS - update to 2.0.3

External References