Authorization bypass through user-controlled key in Chamilo LMS - CVE-2026-61733
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to authorization bypass through a user-controlled key in /api/usergroups/{id}/members when handling requests with a user-supplied group id. A remote user can iterate numeric group identifiers to disclose sensitive information.
Private and closed groups, administrative classes, and cross-portal group rosters may be exposed.