Authorization bypass through user-controlled key in Chamilo LMS - CVE-2026-61537
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to authorization bypass through a user-controlled key in /api/messages/by-group/list when handling requests with a user-supplied groupId query parameter. A remote user can iterate numeric group identifiers and send a crafted request to disclose sensitive information.
Multi-portal deployments are exposed cross-portal because the query does not filter by AccessUrl.