CVE-2026-33703: Chamilo LMS Critical IDOR: Any Authenticated User Can Extract All Users’ Personal Data and API Tokens
Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the /social-network/personal-data/{userId} endpoint allows any authenticated user to access full personal data and API tokens of arbitrary users by modifying the userId parameter. This results in mass disclosure of sensitive user information and credentials, enabling a full platform data breach. This vulnerability is fixed in 2.0.0-RC.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33703?
CVE-2026-33703 is classified as a critical vulnerability due to the potential for unauthorized access to sensitive personal data.
How do I fix CVE-2026-33703?
To fix CVE-2026-33703, update Chamilo LMS to version 2.0.0-RC.3 or newer.
What types of data are exposed in CVE-2026-33703?
CVE-2026-33703 allows an authenticated user to extract personal data and API tokens of all users.
Which versions of Chamilo LMS are affected by CVE-2026-33703?
CVE-2026-33703 affects all versions of Chamilo LMS prior to 2.0.0-RC.3.
Who is impacted by CVE-2026-33703?
Any authenticated user of Chamilo LMS may exploit CVE-2026-33703 to access others' personal information.