CVE-2026-34239: Chamilo Authenticated Remote Code Execution
Chamilo version 1.11.40 and earlier are vulnerable to authenticated remote code execution in the main/inc/ajax/lang.ajax.php path. This endpoint is protected only by apiprotectcoursescript(true), which means any authenticated user enrolled in a course (student, teacher, DRH) can reach it.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34239?
The severity of CVE-2026-34239 is classified as high with a CVSS score of 7.5.
How do I fix CVE-2026-34239?
To fix CVE-2026-34239, upgrade to Chamilo version 1.11.41 or later where the vulnerability has been addressed.
What type of vulnerability is CVE-2026-34239?
CVE-2026-34239 is an authenticated remote code execution vulnerability affecting Chamilo.
Who is affected by CVE-2026-34239?
Any authenticated user enrolled in a Chamilo course, including students and teachers, can exploit CVE-2026-34239.
What is the impact of CVE-2026-34239?
CVE-2026-34239 allows authenticated users to remotely execute code on the server, potentially compromising the entire application.