Executive brief
Chamilo LMS is a popular open-source learning management system used by educational institutions and corporations to deliver online courses. A security flaw allows students or other low-privileged users with API access to upgrade their own accounts to teacher or administrator status. This allows unauthorized users to create and manage courses, modify grades, and access sensitive educational data, undermining the integrity of the learning platform.
Technical details
An improper privilege management vulnerability (CWE-269) exists in the REST API of Chamilo LMS within the `updateUserFromUserName` method in `main/inc/lib/webservices/Rest.php`. While the code prevents users from modifying other accounts, it fails to validate or restrict the fields a user can update on their own profile. Specifically, an authenticated user with a REST API key can send a request to the `update_user_from_username` endpoint to change their `status` field from 5 (Student) to 1 (Teacher/CourseManager), or modify other sensitive fields like `roles` and `auth_source`. This allows for full self-privilege escalation. The issue is addressed in version 1.11.38 by restricting non-admin users from modifying administrative fields.
Affected products
- Chamilo Chamilo LMS <= 1.11.36
Timeline
- 2026-04-10: advisory: GHSA-3gqc-xr75-pcpw published
- 2026-04-10: disclosed: CVE-2026-33706 published
- 2026-04-16: patched: NVD updated with patch information and version 1.11.38 fix