
CVE-2026-34602 Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the /api/course_rel_users endpoint is vulnerable to Insecure Direct Object … https://www.cve.org/CVERecord?id=CVE-2026-34602
Post summary
The text announces CVE-2026-34602 in Chamilo LMS, giving the vulnerable endpoint and type (Insecure Direct Object), but provides no PoC, exploit, or patch information.

