CriticalCritical vulnerability
CVE-2026-45140: Chamilo LMS CStudio upload flow allows unauthenticated remote code execution
GitHub Advisories · officialPublished Sep 17, 2026Risk 50/100
### Impact Ability to run arbitrary code on the server without authentication.
Recommended action
Recommended action
Upgrade affected packages to a patched version: chamilo/chamilo-lms 2.0.1.
Technical details
- Vendor
- Not specified
- Product
- chamilo/chamilo-lms
- Exploitation
- none known
- Evidence
- official
CVSS
9.8
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source