CVE-2026-45140: Chamilo LMS Unauthenticated Remote Code Execution
ID: 6ba02429-236b-5af6-b69e-98884834a349
STIX ID: report--6ba02429-236b-5af6-b69e-98884834a349
Feed Name: CosmicBytez Labs
Threat Score
**Chamilo LMS** contains a critical unauthenticated remote code execution vulnerability (CVE-2026-45140, CVSS 9.8) in the CStudio plugin's project-import upload endpoint that allows arbitrary code execution via crafted archives; affected versions are prior to 2.0.1 and the issue is fixed in Chamilo 2.0.1 — immediate upgrade or disabling/blocking the endpoint is recommended, and administrators should review logs for suspicious uploads and web-root file writes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
