
CVE-2026-33707 Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password reset mechanism generates tokens using sha1($email) with no random … https://www.cve.org/CVERecord?id=CVE-2026-33707
Post summary
The CVE-2026-33707 vulnerability in Chamilo LMS allows an attacker to predict password reset tokens because they are generated using sha1($email) with no random component, affecting versions prior to 1.11.38 and 2.0.0-RC.3, with no mention of patches or active exploitation.



