Junglewise Threat Intelligence

CVE-2026-34160: Chamilo LMS unauthenticated SSRF in PENS plugin

CVE-2026-34160 · Severity: high · CVSS 8.6 · Published 2026-04-14

Technologies: Chamilo Lms. Vendors: Chamilo.

Executive brief

Chamilo LMS, an open-source learning management system, contains a security flaw in its PENS plugin. An unauthenticated attacker can force the server to make requests to internal network locations that are normally protected. This could allow an attacker to steal sensitive cloud credentials, probe internal databases, or access private administrative services, potentially leading to a broader compromise of the organization's infrastructure.

Technical details

An unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Chamilo LMS versions prior to 2.0.0-RC.3 within the PENS (Package Exchange Notification Services) plugin. The endpoint at 'public/plugin/Pens/pens.php' fails to authenticate requests and accepts a user-controlled 'package-url' parameter. This parameter is processed via curl without filtering for private or reserved IP ranges. Attackers can exploit this to perform internal network reconnaissance, access cloud metadata services (e.g., 169.254.169.254) to retrieve IAM credentials, or interact with internal APIs via the 'receipt' and 'alerts' callback parameters. The issue is fixed in version 2.0.0-RC.3 by implementing stricter URL validation logic.

Affected products

  • Chamilo Chamilo LMS < 2.0.0-RC.3

Timeline

  • 2026-04-01: patched: Version 2.0.0-RC.3 released
  • 2026-04-14: disclosed: Security advisory published
  • 2026-04-14: advisory: CVE-2026-34160 assigned

References

Related threats