Junglewise Threat Intelligence

CVE-2026-33698: Chamilo LMS unauthenticated RCE in main/install directory

CVE-2026-33698 · Severity: critical · CVSS 9.8 · Published 2026-04-10

Technologies: Chamilo Lms. Vendors: Chamilo.

Executive brief

Chamilo LMS is a popular open-source learning management system used by educational institutions and businesses to deliver online courses. A critical vulnerability allows unauthenticated attackers to bypass security restrictions and execute malicious code on the server. This could lead to a complete system takeover, unauthorized access to student and teacher data, or the modification of course content.

Technical details

A remote code execution (RCE) vulnerability exists in Chamilo LMS due to improper access controls and input handling in the 'main/install/' directory. An unauthenticated attacker can chain multiple flaws to bypass restrictions that normally block PHP execution in the installation folder. By sending specially crafted requests, the attacker can modify existing configuration files (such as app/config/configuration.php) or create new malicious files on the server. This vulnerability specifically affects installations where the 'main/install/' directory was not removed after the initial setup and remains web-accessible. The fix involves stricter validation of installer variables and removing the vulnerable scripts.

Affected products

  • Chamilo Chamilo LMS < 1.11.38

Timeline

  • 2026-03-23: patched: Fix committed to repository
  • 2026-04-10: disclosed: Initial advisory published
  • 2026-04-10: advisory: GitHub Security Advisory published
  • 2026-04-16: other: NIST analysis completed

References

Related threats