CVE-2026-31940: Session Fixation in Chamilo LMS
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, in main/lp/aicchacp.php, user-controlled request parameters are directly used to set the PHP session ID before loading global bootstrap. This leads to session fixation. This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-31940?
CVE-2026-31940 is classified as a high severity vulnerability due to its potential for session fixation attacks.
How do I fix CVE-2026-31940?
To fix CVE-2026-31940, update Chamilo LMS to version 1.11.38 or 2.0.0-RC.3 or later.
What systems are affected by CVE-2026-31940?
CVE-2026-31940 affects Chamilo LMS versions prior to 1.11.38 and 2.0.0-RC.3.
What type of vulnerability is CVE-2026-31940?
CVE-2026-31940 is a session fixation vulnerability that allows attackers to hijack user sessions.
Who is responsible for addressing CVE-2026-31940?
The Chamilo team is responsible for addressing and patching CVE-2026-31940 in their software releases.