CVE-2026-32892Disclosure(chamilo / chamilo_lms)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an OS Command Injection vulnerability in the file move function. The move() function in fileManage.lib.php passes user-controlled path values directly into exec() shell commands without using escapeshellarg(). When a user moves a document via document.php, the move_to POST parameter — which only passes through Security::remove_XSS() (an HTML-only filter) — is concatenated directly into shell commands such as exec("mv $source $target"). By default, Chamilo allows all authenticated users to create courses (allow_users_to_create_courses = true). Any user who is a teacher in a course (including self-created courses) can move documents, making this vulnerability exploitable by any authenticated user. The attacker must first place a directory with shell metacharacters in its name on the filesystem (achievable via Course Backup Import), then move a document into that directory to trigger arbitrary command execution as the web server user (www-data). This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chamilo_lms

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Exploit: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-04-10); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
chamilo_lms

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-10: 3Mentions · 2026-04-11: 1PoC Mentioned / Linked · 2026-04-10: 1Technical Details · 2026-04-10: 3Technical Details · 2026-04-11: 104-1004-11
Signal classification2 categories
Disclosure
375.0%
Exploit
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-103
Disclosure2Exploit1
2026-04-111
Disclosure1
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32892 OS Command Injection in Chamilo LMS Prior to 1.11.38 and 2.0.0-RC.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32892

    Post summary

    The text announces CVE-2026-32892 as an OS command injection vulnerability affecting Chamilo LMS versions prior to 1.11.38 and 2.0.0‑RC.3, directing readers to a details page.

    0000039
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32892 Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an OS Command Injection vulnerability in the file move function. Th… https://www.cve.org/CVERecord?id=CVE-2026-32892

    Post summary

    The text announces CVE‑2026‑32892 as an OS command injection flaw in Chamilo LMS’s move function affecting versions before 1.11.38 and 2.0.0‑RC.3, without providing PoC, exploit, or mitigation details.

    00000107
    57.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-32892: CRITICAL] Chamilo LMS had an OS Command Injection vulnerability in versions prior to 1.11.38 and 2.0.0-RC.3, allowing authenticated users to execute arbitrary commands as the web server user.#cve,CVE-2026-32892,#cybersecurity https://cvefind.com/CVE-2026-32892

    Post summary

    The text announces a critical OS command injection vulnerability in specific Chamilo LMS versions, detailing how authenticated users can exploit it.

    0000049
    619 followersView on X
  • 0day Signal@0dayPublishing
    Exploit

    🚨 CVE-2026-32892: OS Command Injection in Chamilo ... Default teacher perms + course creation = RCE via unescaped exec() in file moves - any auth'd user can pop shells throu... https://zerodaysignal.com/vulnerability/CVE-2026-32892 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-32892 reveals an OS command injection flaw in Chamilo that lets any authenticated user execute arbitrary commands via an unescaped exec() call, with a reference link provided for detailed information.

    0000075
    204 followersView on X
CPE platform detail11 entries

11 of 11 entries

PartVendorProductVersionTarget SWTarget HW
Appchamilochamilo_lms---
Appchamilochamilo_lms2.0.0--
Appchamilochamilo_lms2.0.0--
Appchamilochamilo_lms2.0.0--
Appchamilochamilo_lms2.0.0--
Appchamilochamilo_lms2.0.0--
Appchamilochamilo_lms2.0.0--
Appchamilochamilo_lms2.0.0--
Appchamilochamilo_lms2.0.0--
Appchamilochamilo_lms2.0.0--
Appchamilochamilo_lms2.0.0--

Explore more