CVE-2026-29041Disclosure(chamilo / chamilo_lms)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch chamilo chamilo_lms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Chamilo is a learning management system. Prior to version 1.11.34, Chamilo LMS is affected by an authenticated remote code execution vulnerability caused by improper validation of uploaded files. The application relies solely on MIME-type verification when handling file uploads and does not adequately validate file extensions or enforce safe server-side storage restrictions. As a result, an authenticated low-privileged user can upload a crafted file containing executable code and subsequently execute arbitrary commands on the server. This issue has been patched in version 1.11.34.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chamilo_lms

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 4 mentions (2026-03-06); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
chamilo_lms

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-03-06: 4Mentions · 2026-03-10: 1Mentions · 2026-03-11: 1Patch / Workaround · 2026-03-06: 1Technical Details · 2026-03-06: 4Technical Details · 2026-03-10: 1Technical Details · 2026-03-11: 103-0603-1003-11
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-064
Disclosure3Patch1
2026-03-101
Disclosure1
2026-03-111
Disclosure1
Full discourse6 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-29041 (CVSS:8.8, HIGH) is Analyzed. Chamilo is a learning management system. Prior to version 1.11.34, Chamilo LMS is affected by an authenticated remote co..https://nvd.nist.gov/vuln/detail/CVE-2026-29041 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet references CVE-2026-29041, noting its high CVSS score and impact on Chamilo LMS before version 1.11.34, but shares no PoC, exploit code, patch, or active exploitation details.

    0000012
    172 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Chamilo LMS, Authenticated Remote Code Execution, #CVE-2026-29041 (High) https://dailycve.com/chamilo-lms-authenticated-remote-code-execution-cve-2026-29041-high/

    Post summary

    The tweet announces the discovery of an authenticated remote code execution vulnerability (CVE-2026-29041) in Chamilo LMS, providing basic technical details without mentioning exploits, patches, or active attack reports.

    0000034
    166 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29041 Chamilo is a learning management system. Prior to version 1.11.34, Chamilo LMS is affected by an authenticated remote code execution vulnerability caused by improper … https://www.cve.org/CVERecord?id=CVE-2026-29041

    Post summary

    CVE‑2026‑29041 reveals an authenticated remote code execution flaw affecting Chamilo LMS versions older than 1.11.34.

    00000116
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-29041 - High Chamilo is a learning management system. Prior to version 1.11.34, Chamilo LMS is affected by an authenticated remote code execution vulnerability caused by improper validation of uploaded fi... https://www.thehackerwire.com/vulnerability/CVE-2026-29041/ https://t.co/CtyDfjGQPZ

    Post summary

    The tweet announces a high‑severity authenticated RCE vulnerability (CVE‑2026‑29041) in Chamilo LMS before version 1.11.34, with no PoC, exploit, or patch information provided.

    0000033
    125 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-29041 - Chamilo: Authenticated Remote Code Execution via Unrestricted File Upload Intel Report: https://ift.tt/062Q5Ni

    Post summary

    The tweet announces CVE-2026-29041 affecting Chamilo, describing an authenticated RCE through unrestricted file upload, and links to an Intel Report, but does not provide PoC, exploit, or patch information.

    0000033
    343 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-29041: HIGH] Chamilo LMS prior to version 1.11.34 had a critical remote code execution vulnerability due to improper file upload validation. Always update to the latest secure version.#cve,CVE-2026-29041,#cybersecurity https://cvefind.com/CVE-2026-29041

    Post summary

    The tweet announces a critical RCE vulnerability in Chamilo LMS prior to v1.11.34 and urges users to update to the latest secure version.

    0000060
    597 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appchamilochamilo_lms---

Explore more