CVE-2026-33706: Chamilo LMS has a REST API Self-Privilege Escalation (Student → Teacher)
Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user with a REST API key can modify their own status field via the updateuserfromusername endpoint. A student (status=5) can change their status to Teacher/CourseManager (status=1), gaining course creation and management privileges. This vulnerability is fixed in 1.11.38.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33706?
CVE-2026-33706 is considered a critical vulnerability due to its potential for privilege escalation within the Chamilo LMS.
How do I fix CVE-2026-33706?
To fix CVE-2026-33706, upgrade Chamilo LMS to version 1.11.38 or later.
Who is affected by CVE-2026-33706?
Any authenticated user of Chamilo LMS versions prior to 1.11.38 is affected by CVE-2026-33706.
What type of vulnerability is CVE-2026-33706?
CVE-2026-33706 is a REST API self-privilege escalation vulnerability in Chamilo LMS.
Can students exploit CVE-2026-33706?
Yes, students can exploit CVE-2026-33706 to elevate their status to that of a teacher using the REST API.