CVE-2026-45140: Chamilo LMS CStudio upload flow allows unauthenticated remote code execution
Impact Ability to run arbitrary code on the server without authentication.
Other sources
Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory does not identify the affected endpoint, component, input, or exploitation mechanism. This issue is fixed in version 2.0.1.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/chamilo/chamilo-lmsto a version that resolves this vulnerability.Fixed in 2.0.1 - Upgrade
Upgrade
Chamilo LMSto a version that resolves this vulnerability.Fixed in 2.0.1
Event History
Frequently Asked Questions
Which deployments should be treated as affected?
Chamilo LMS deployments running a version earlier than 2.0.1 should be treated as affected. The listed software includes Chamilo LMS and the composer/chamilo/chamilo-lms package.
Does an attacker need an account or user interaction to exploit this issue?
No. The issue is described as exploitable by an unauthenticated remote attacker, and the severity vector indicates network access with no privileges or user interaction required.
What is the available remediation?
Upgrade Chamilo LMS to version 2.0.1, which fixes the issue. The advisory does not provide an alternative mitigation for environments that cannot immediately upgrade.