CVE-2026-33707Disclosure(chamilo / chamilo_lms)

LOWCVSS 9.8 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch chamilo chamilo_lms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password reset mechanism generates tokens using sha1($email) with no random component, no expiration, and no rate limiting. An attacker who knows a user's email can compute the reset token and change the victim's password without authentication. This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-640

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chamilo_lms

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
chamilo_lms

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-04-10: 4Patch / Workaround · 2026-04-10: 1Technical Details · 2026-04-10: 404-10
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets5 URLs
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-33707 Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password reset mechanism generates tokens using sha1($email) with no random … https://www.cve.org/CVERecord?id=CVE-2026-33707

    Post summary

    The CVE-2026-33707 vulnerability in Chamilo LMS allows an attacker to predict password reset tokens because they are generated using sha1($email) with no random component, affecting versions prior to 1.11.38 and 2.0.0-RC.3, with no mention of patches or active exploitation.

    0001081
    57.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-33707 Unauthenticated Password Reset via Predictable Token Generation i... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33707 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet cites CVE‑2026‑33707 and links to a vulnerability page, offering a brief title about an unauthenticated password reset flaw but none of the other categories such as PoC, exploit, or patch.

    0000035
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33707: CRITICAL] Chamilo LMS versions prior to 1.11.38 and 2.0.0-RC.3 had a vulnerability allowing unauthorized password changes. Ensure to update to the latest versions for improved cyber security.#cve,CVE-2026-33707,#cybersecurity https://cvefind.com/CVE-2026-33707

    Post summary

    The tweet discloses a critical CVE in Chamilo LMS that permits unauthorized password changes and urges users to update to patched versions.

    0000038
    619 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33707: Weak Password Recovery Mechanism... sha1($email) as password reset tokens? Chamilo devs basically handed attackers a skeleton key to every account - zero e... https://zerodaysignal.com/vulnerability/CVE-2026-33707 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post highlights Chamilo’s weak password recovery mechanism using SHA‑1(email) as reset tokens, effectively exposing all accounts; the vulnerability is being disclosed via an external link.

    0000060
    204 followersView on X
CPE platform detail11 entries

11 of 11 entries

PartVendorProductVersionTarget SWTarget HW
Appchamilochamilo_lms---
Appchamilochamilo_lms2.0.0--
Appchamilochamilo_lms2.0.0--
Appchamilochamilo_lms2.0.0--
Appchamilochamilo_lms2.0.0--
Appchamilochamilo_lms2.0.0--
Appchamilochamilo_lms2.0.0--
Appchamilochamilo_lms2.0.0--
Appchamilochamilo_lms2.0.0--
Appchamilochamilo_lms2.0.0--
Appchamilochamilo_lms2.0.0--

Explore more