CVE-2026-34239
Chamilo Authenticated Remote Code Execution
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Chamilo version 1.11.40 and earlier are vulnerable to authenticated remote code execution in the main/inc/ajax/lang.ajax.php path. This endpoint is protected only by `api_protect_course_script(true)`, which means any authenticated user enrolled in a course (student, teacher, DRH) can reach it.
| CWE | CWE-285 |
| Vendor | chamilo |
| Product | chamilo-lms |
| Published | Jul 20, 2026 |
| Last Updated | Jul 20, 2026 |
Stay Ahead of the Next One
Get instant alerts for chamilo chamilo-lms
Be the first to know when new unknown vulnerabilities affecting chamilo chamilo-lms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
chamilo / chamilo-lms
<= 1.11.40