CVE-2026-34602Disclosure(chamilo / chamilo_lms)

LOWCVSS 7.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the /api/course_rel_users endpoint is vulnerable to Insecure Direct Object Reference (IDOR), allowing an authenticated attacker to modify the user parameter in the request body to enroll any arbitrary user into any course without proper authorization checks. The backend trusts the user-supplied input for the user field and performs no server-side verification that the requester owns the referenced user ID or has permission to act on behalf of other users. This enables unauthorized manipulation of user-course relationships, potentially granting unintended access to course materials, bypassing enrollment controls, and compromising platform integrity. This issue has been fixed in version 2.0.0-RC.3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chamilo_lms

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
chamilo_lms

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-15: 2Technical Details · 2026-04-15: 204-15
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-34602 Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the /api/course_rel_users endpoint is vulnerable to Insecure Direct Object … https://www.cve.org/CVERecord?id=CVE-2026-34602

    Post summary

    The text announces CVE-2026-34602 in Chamilo LMS, giving the vulnerable endpoint and type (Insecure Direct Object), but provides no PoC, exploit, or patch information.

    0000080
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-34602 Insecure Direct Object Reference in Chamilo LMS Prior to 2.0.0-RC.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-34602

    Post summary

    The snippet references CVE-2026-34602 and describes it as an insecure direct object reference affecting Chamilo LMS versions before 2.0.0-RC.3, but it lacks details on PoC, exploitation, or mitigation.

    0000040
    4.0K followersView on X
CPE platform detail11 entries

11 of 11 entries

PartVendorProductVersionTarget SWTarget HW
Appchamilochamilo_lms---
Appchamilochamilo_lms2.0.0--
Appchamilochamilo_lms2.0.0--
Appchamilochamilo_lms2.0.0--
Appchamilochamilo_lms2.0.0--
Appchamilochamilo_lms2.0.0--
Appchamilochamilo_lms2.0.0--
Appchamilochamilo_lms2.0.0--
Appchamilochamilo_lms2.0.0--
Appchamilochamilo_lms2.0.0--
Appchamilochamilo_lms2.0.0--

Explore more