
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1106 is an improper authorization vulnerability in Chamilo LMS affecting the deleteLegal function within src/CoreBundle/Controller/SocialController.php (Legal Consent Handler component). It affects Chamilo LMS versions up to and including 2.0.0 Beta 1 (all pre-2.0.0 releases, plus alpha1–alpha5 and beta1). The vulnerability was disclosed on January 17–18, 2026, assigned by VulDB, with the vendor reportedly unresponsive to disclosure. It carries a CVSS v3.1 base score of 5.4 (Medium) and a CVSS v4.0 score of 2.1 (Low) (VulDB, Red Hat CVE).
The root cause is improper authorization (CWE-285) combined with incorrect privilege assignment (CWE-266) in the deleteLegal function of SocialController.php. An authenticated attacker can manipulate the userId argument in the request to the Legal Consent Handler endpoint, causing the application to delete legal consent records belonging to other users without verifying that the requester has the appropriate privileges. The attack requires only low-level authenticated access and no user interaction, making it straightforward to exploit remotely. A proof-of-concept exploit has been publicly released (VulDB, note-hxlab writeup).
Successful exploitation allows an authenticated attacker to delete legal consent records of arbitrary users, undermining platform integrity and compliance records (e.g., GDPR consent logs). While there is no direct confidentiality impact (no data disclosure), the integrity and availability of consent data are affected — attackers can erase evidence of user consent or remove records needed for regulatory compliance. The scope is limited to the Chamilo LMS application itself, with no evidence of lateral movement potential beyond the application layer (VulDB, Feedly/EUVD).
A public proof-of-concept exploit has been released and is referenced in VulDB and the NVD entry, with CVSS v4.0 exploit maturity rated as "Proof of Concept" (VulDB). The EPSS score is approximately 0.034% (0.000340), indicating a low but non-zero probability of exploitation in the wild. There is no current evidence of active in-the-wild exploitation, threat actor attribution, or inclusion in the CISA KEV catalog. The vendor was reportedly unresponsive to the initial disclosure, leaving no official patch available at time of publication (VulDB, Red Hat CVE).
deleteLegal function in src/CoreBundle/Controller/SocialController.php.deleteLegal endpoint, manipulating the userId parameter to reference a victim user's ID rather than the attacker's own.userId, resulting in deletion of the target user's legal consent record (VulDB, note-hxlab writeup).deleteLegal endpoint (within SocialController.php) where the userId parameter does not match the session user's own ID; repeated or bulk deletion requests from a single account targeting multiple user IDs.No official vendor patch has been released as of the disclosure date, as the Chamilo vendor was reportedly unresponsive to the disclosure (VulDB). Organizations should monitor for a patched release from the Chamilo project and upgrade as soon as one becomes available. As an interim workaround, administrators can restrict access to the Legal Consent Handler endpoint via web server rules (e.g., limiting access to administrator roles only), implement additional server-side authorization checks, or disable the legal consent deletion feature if not required. Monitoring application logs for anomalous deleteLegal requests is also recommended.
The vulnerability was assigned and disclosed by VulDB, with the researcher noting that the Chamilo vendor did not respond to the disclosure. A Bluesky post referencing the CVE was observed shortly after publication, and the vulnerability was picked up by aggregators including Vulners, Tenable, and Red Hat's CVE tracker. No significant vendor statement, major media coverage, or notable researcher commentary beyond the initial VulDB submission has been identified (VulDB, Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."