CVE-2026-45140 is an unauthenticated remote code execution vulnerability in Chamilo LMS versions prior to 2.0.1. The CStudio upload flow permits a remote attacker to execute arbitrary code on the server. The vulnerable endpoint, precise input handling flaw, and full exploitation mechanism have not been publicly specified.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This seven-file repository is a standalone Python proof of concept for CVE-2026-45140 affecting Chamilo LMS versions through 2.0.0. The principal entry point, CVE-2026-45140-Abraxas-Labs.py, uses Python's http.client to POST a fixed plaintext marker to the unauthenticated CStudio BigUpload endpoint. It supplies a traversal sequence in the key query parameter to target public/poc-witness.txt, then issues a GET for that file and exits successfully only when the marker is present. Thus, the implemented capability is unauthenticated arbitrary file write / web-accessible file placement; it demonstrates the prerequisite commonly associated with RCE but does not itself submit PHP, execute commands, create persistence, or make outbound connections. The script is hardcoded to 127.0.0.1:8088 and is therefore a lab-oriented POC rather than a configurable scanner or exploitation framework module. README.md documents the vulnerability, conditions, remediation to 2.0.1 or later, and expected witness behavior. The lab directory contains Docker Compose, Apache virtual-host configuration, and a Dockerfile/base-image pin. Compose exposes only 127.0.0.1:8088, mounts a local Chamilo tree at /var/www/html, configures public/ as the document root, and provisions MySQL. No framework such as Metasploit or Nuclei is used.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical unauthenticated remote code-execution vulnerability in Chamilo LMS versions before 2.0.1. Successful exploitation allows arbitrary code execution on the server.
A critical unauthenticated remote code execution vulnerability in Chamilo LMS versions prior to 2.0.1. The advisory does not identify the affected endpoint, component, input, or exploitation mechanism. Its CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
An unauthenticated remote code execution vulnerability in the Chamilo LMS CStudio upload flow, allowing arbitrary code execution on the affected server without authentication.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.