Chamilo LMS disclosed two high-severity vulnerabilities affecting versions prior to 1.11.38, including CVE-2026-33698, an unauthenticated remote code execution issue tied to the main/install/ directory, and CVE-2026-31939, a path traversal flaw in main/exercise/savescores.php that can be abused for arbitrary file deletion. The RCE issue stems from a chained attack that can re-enable otherwise blocked PHP execution in the installer path; if main/install/ remains present and readable, an attacker can modify existing files or create new ones within the permissions of the web server.
The second flaw allows user-controlled input from $_REQUEST['test'] to be concatenated into a filesystem path without proper canonicalization or traversal checks, enabling deletion of arbitrary files with low attack complexity. The vulnerabilities were classified under CWE-552, CWE-22, and CWE-73, and both were addressed in Chamilo LMS 1.11.38 through vendor patches and a coordinated GitHub security advisory, making upgrade and removal or restriction of exposed installer files an urgent priority for affected deployments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-10, a new Chamilo LMS flaw, CVE-2026-32892, was disclosed describing an authenticated OS command injection in the document move feature caused by unsafe use of exec() in fileManage.lib.php. The issue affects versions prior to 1.11.38 and 2.0.0-RC.3 and was fixed in versions 1.11.38 and 2.0.0-RC.3.
On April 10, 2026, GitHub security advisories disclosed CVE-2026-33698, an unauthenticated RCE affecting Chamilo LMS when the main/install directory remains present and readable, and CVE-2026-31939, a path traversal vulnerability that can lead to arbitrary file deletion. Both advisories state that affected versions are those prior to 1.11.38.
Chamilo addressed two security flaws affecting versions prior to 1.11.38: an unauthenticated remote code execution issue involving the main/install directory and a path traversal flaw in main/exercise/savescores.php that could enable arbitrary file deletion. The fix was released in Chamilo LMS version 1.11.38.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.