logo

CVE-2026-45140: Chamilo LMS Unauthenticated Remote Code Execution

ID: 6ba02429-236b-5af6-b69e-98884834a349

STIX ID: report--6ba02429-236b-5af6-b69e-98884834a349

Feed Name: CosmicBytez Labs

Threat Score
85/100

Date Published: 2026-09-18

Date Updated: 2026-09-19

...
...

**Chamilo LMS** contains a critical unauthenticated remote code execution vulnerability (CVE-2026-45140, CVSS 9.8) in the CStudio plugin's project-import upload endpoint that allows arbitrary code execution via crafted archives; affected versions are prior to 2.0.1 and the issue is fixed in Chamilo 2.0.1 — immediate upgrade or disabling/blocking the endpoint is recommended, and administrators should review logs for suspicious uploads and web-root file writes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.