CVE-2026-1106: 
Chamilo vulnerability analysis and mitigation

Overview

CVE-2026-1106 is an improper authorization vulnerability in Chamilo LMS affecting the deleteLegal function within src/CoreBundle/Controller/SocialController.php (Legal Consent Handler component). It affects Chamilo LMS versions up to and including 2.0.0 Beta 1 (all pre-2.0.0 releases, plus alpha1–alpha5 and beta1). The vulnerability was disclosed on January 17–18, 2026, assigned by VulDB, with the vendor reportedly unresponsive to disclosure. It carries a CVSS v3.1 base score of 5.4 (Medium) and a CVSS v4.0 score of 2.1 (Low) (VulDB, Red Hat CVE).

Technical details

The root cause is improper authorization (CWE-285) combined with incorrect privilege assignment (CWE-266) in the deleteLegal function of SocialController.php. An authenticated attacker can manipulate the userId argument in the request to the Legal Consent Handler endpoint, causing the application to delete legal consent records belonging to other users without verifying that the requester has the appropriate privileges. The attack requires only low-level authenticated access and no user interaction, making it straightforward to exploit remotely. A proof-of-concept exploit has been publicly released (VulDB, note-hxlab writeup).

Impact

Successful exploitation allows an authenticated attacker to delete legal consent records of arbitrary users, undermining platform integrity and compliance records (e.g., GDPR consent logs). While there is no direct confidentiality impact (no data disclosure), the integrity and availability of consent data are affected — attackers can erase evidence of user consent or remove records needed for regulatory compliance. The scope is limited to the Chamilo LMS application itself, with no evidence of lateral movement potential beyond the application layer (VulDB, Feedly/EUVD).

Exploitability

A public proof-of-concept exploit has been released and is referenced in VulDB and the NVD entry, with CVSS v4.0 exploit maturity rated as "Proof of Concept" (VulDB). The EPSS score is approximately 0.034% (0.000340), indicating a low but non-zero probability of exploitation in the wild. There is no current evidence of active in-the-wild exploitation, threat actor attribution, or inclusion in the CISA KEV catalog. The vendor was reportedly unresponsive to the initial disclosure, leaving no official patch available at time of publication (VulDB, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Chamilo LMS instances running versions up to 2.0.0 Beta 1 using web search, Shodan, or Censys, looking for the Chamilo login page.
  2. Authenticate: Obtain or register a low-privileged user account on the target Chamilo LMS instance.
  3. Identify the target endpoint: Locate the Legal Consent Handler endpoint that invokes the deleteLegal function in src/CoreBundle/Controller/SocialController.php.
  4. Craft malicious request: Send an authenticated HTTP request to the deleteLegal endpoint, manipulating the userId parameter to reference a victim user's ID rather than the attacker's own.
  5. Achieve unauthorized deletion: The application fails to verify that the authenticated user owns the specified userId, resulting in deletion of the target user's legal consent record (VulDB, note-hxlab writeup).

Indicators of compromise

  • Logs: Web server or application logs showing authenticated requests to the deleteLegal endpoint (within SocialController.php) where the userId parameter does not match the session user's own ID; repeated or bulk deletion requests from a single account targeting multiple user IDs.
  • Application Data: Unexpected deletion of legal consent records in the Chamilo database, particularly for users who did not initiate the deletion themselves; gaps or anomalies in the legal consent audit trail.
  • Network: Unusual patterns of authenticated POST/GET requests to the Legal Consent Handler endpoint from a single IP or user account in a short time window.

Mitigation and workarounds

No official vendor patch has been released as of the disclosure date, as the Chamilo vendor was reportedly unresponsive to the disclosure (VulDB). Organizations should monitor for a patched release from the Chamilo project and upgrade as soon as one becomes available. As an interim workaround, administrators can restrict access to the Legal Consent Handler endpoint via web server rules (e.g., limiting access to administrator roles only), implement additional server-side authorization checks, or disable the legal consent deletion feature if not required. Monitoring application logs for anomalous deleteLegal requests is also recommended.

Community reactions

The vulnerability was assigned and disclosed by VulDB, with the researcher noting that the Chamilo vendor did not respond to the disclosure. A Bluesky post referencing the CVE was observed shortly after publication, and the vulnerability was picked up by aggregators including Vulners, Tenable, and Red Hat's CVE tracker. No significant vendor statement, major media coverage, or notable researcher commentary beyond the initial VulDB submission has been identified (VulDB, Red Hat CVE).

Additional resources


Source: This report was generated using AI

Related Chamilo vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45140CRITICAL9.8
  • PHP logoPHP
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-39878CRITICAL9.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-45143CRITICAL9
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesSep 17, 2026
CVE-2026-34239HIGH7.5
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoYesJul 20, 2026
CVE-2026-82535MEDIUM5.3
  • Chamilo logoChamilo
  • cpe:2.3:a:chamilo:chamilo_lms
NoNoSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management