CRITICAL
9.8 CVE-2026-45140 Published 17 Sept 2026
Chamilo LMS Arbitrary Code Execution
Worried this affects your website?
Chamilo LMS, an open-source learning management system, is affected by a critical security vulnerability.
Prior to version 2.0.1, the system allows an unauthenticated remote attacker to execute arbitrary code on the server.
The authoritative advisory does not specify the affected endpoint, component, input, or exploitation mechanism.
This issue is fixed in version 2.0.1.
Reference: CVE-2026-45140 on NVD
← Back to Security News