CVE-2026-32892: OS Command Injection in Chamilo LMS 1.11.36
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an OS Command Injection vulnerability in the file move function. The move() function in fileManage.lib.php passes user-controlled path values directly into exec() shell commands without using escapeshellarg(). When a user moves a document via document.php, the moveto POST parameter — which only passes through Security::removeXSS() (an HTML-only filter) — is concatenated directly into shell commands such as exec("mv $source $target"). By default, Chamilo allows all authenticated users to create courses (allowuserstocreatecourses = true). Any user who is a teacher in a course (including self-created courses) can move documents, making this vulnerability exploitable by any authenticated user. The attacker must first place a directory with shell metacharacters in its name on the filesystem (achievable via Course Backup Import), then move a document into that directory to trigger arbitrary command execution as the web server user (www-data). This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32892?
CVE-2026-32892 is considered to have a critical severity due to the potential for OS Command Injection.
How do I fix CVE-2026-32892?
To fix CVE-2026-32892, upgrade Chamilo LMS to version 1.11.38 or 2.0.0-RC.3 or later.
What versions of Chamilo LMS are affected by CVE-2026-32892?
CVE-2026-32892 affects Chamilo LMS versions prior to 1.11.38 and 2.0.0-RC.3.
What type of vulnerability is CVE-2026-32892?
CVE-2026-32892 is an OS Command Injection vulnerability that can be exploited through the move function.
Where can I find more information about CVE-2026-32892?
More information about CVE-2026-32892 can typically be found in security advisories from the vendor.