CVE Watchtower

← Back to CVE List

CVE-2026-45140NVD

Description

Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory does not identify the affected endpoint, component, input, or exploitation mechanism. This issue is fixed in version 2.0.1.
Severity Level
CRITICAL (9.8)
Published Date
17/09/2026
Last Modified
18/09/2026
Exploitation Status
????
EPSS Score
0.98% (percentile 60.6%)

CVSS Base Metrics

CVSS v3 (3.1)
CRITICAL 9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

CWE-22 - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-94 - CWE-94: Improper Control of Generation of Code ('Code Injection')CWE-219 - CWE-219: Storage of File with Sensitive Data Under Web RootCWE-434 - CWE-434: Unrestricted Upload of File with Dangerous Type

Affected & Patched Versions

ProductAffected VersionsPatched Version
chamilo chamilo-lms< 2.0.1N/A
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.