CVE-2026-33698: Chamilo LMS affected by unauthenticated RCE in main/install folder
Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise-blocked PHP code from the main/install/ directory and allow an unauthenticated attacker to modify existing files or create new files where allowed by system permissions. This only affects portals with the main/install/ directory still present and read-accessible. This vulnerability is fixed in 1.11.38.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33698?
CVE-2026-33698 is classified as a critical severity vulnerability due to its potential for unauthenticated remote code execution.
How do I fix CVE-2026-33698?
To fix CVE-2026-33698, upgrade Chamilo LMS to version 1.11.38 or a later version.
What type of vulnerability is CVE-2026-33698?
CVE-2026-33698 is an unauthenticated remote code execution vulnerability that affects the Chamilo LMS.
Which systems are affected by CVE-2026-33698?
CVE-2026-33698 affects all versions of Chamilo LMS prior to 1.11.38.
Can an attacker exploit CVE-2026-33698 without authentication?
Yes, an attacker can exploit CVE-2026-33698 without authentication, allowing malicious actions to be performed on the server.