CVE-2026-39878
Chamilo LMS versions 1.11.38 and earlier have a stored cross‑site scripting flaw in the user registration form. An unauthenticated attacker can inject JavaScript that runs in an administrator’s browser, allowing the attacker to hijack the admin account. The issue has been fixed in version 1.11.40.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Chamilo Learning Management System (LMS) versions 1.11.38 and earlier.
Real-world impact
An attacker can run arbitrary JavaScript in an admin’s browser session, enabling full takeover of the platform’s administrative account and all associated privileges.
Why this severity
The CVSS score of 9.3 reflects that the vulnerability can be exploited over the network (AV:N), requires low effort (AC:L), no user interaction beyond the admin’s browser (UI:R), and changes the scope (S:C). It grants high confidentiality and integrity impact (C:H, I:H) while not affecting availability.
What to do about it
- 01Upgrade Chamilo LMS to version 1.11.40 or later.
NVD-referenced vendor advisory
Timeline
- Jul 20, 2026 · 13d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 13d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 22, 2026 · 11d agoAdvisory updatedThe NVD record was last revised.