CVE-2026-32931: Chamilo LMS has Arbitrary File Upload via MIME-Only Validation in Exercise Sound Upload Leads to RCE
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an unrestricted file upload vulnerability in the exercise sound upload function allows an authenticated teacher to upload a PHP webshell by spoofing the Content-Type header to audio/mpeg. The uploaded file retains its original .php extension and is placed in a web-accessible directory, enabling Remote Code Execution as the web server user (www-data). This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32931?
CVE-2026-32931 has a high severity due to its potential for remote code execution (RCE) via arbitrary file uploads.
How do I fix CVE-2026-32931?
To fix CVE-2026-32931, upgrade Chamilo LMS to version 1.11.38 or later, or version 2.0.0-RC.3 or later.
Who is affected by CVE-2026-32931?
CVE-2026-32931 affects authenticated teachers using Chamilo LMS versions earlier than 1.11.38 and 2.0.0-RC.3.
What type of vulnerability is CVE-2026-32931?
CVE-2026-32931 is an unrestricted file upload vulnerability that allows for arbitrary file uploads.
What can happen if CVE-2026-32931 is exploited?
If exploited, CVE-2026-32931 allows an attacker to execute arbitrary code on the server, posing a severe security risk.