🔐 CVE Alert

CVE-2026-33703

UNKNOWN 0.0

Chamilo LMS Critical IDOR: Any Authenticated User Can Extract All Users’ Personal Data and API Tokens

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
11th

Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the /social-network/personal-data/{userId} endpoint allows any authenticated user to access full personal data and API tokens of arbitrary users by modifying the userId parameter. This results in mass disclosure of sensitive user information and credentials, enabling a full platform data breach. This vulnerability is fixed in 2.0.0-RC.3.

CWE CWE-639
Vendor chamilo
Product chamilo-lms
Published Apr 10, 2026
Last Updated Apr 14, 2026
Stay Ahead of the Next One

Get instant alerts for chamilo chamilo-lms

Be the first to know when new unknown vulnerabilities affecting chamilo chamilo-lms are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

chamilo / chamilo-lms
< 2.0.0-RC.3

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-27x6-c5c7-gpf5