{"id":"CVE-2026-45140","title":"Chamilo LMS is an open-source learning management system","summary":"Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory does not identify the affected endpoint, …","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-22","CWE-94","CWE-219","CWE-434"],"vendor":"chamilo","product":"chamilo-lms","affected":["chamilo-lms < 2.0.1"],"patched":["chamilo/chamilo-lms 2.0.1"],"published":"2026-09-17","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:16:41.093","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-45140","references":[{"url":"https://github.com/chamilo/chamilo-lms/commit/4bdba1b9a8820bd70c0809317775d7f6eaa79844","label":"security-advisories@github.com"},{"url":"https://github.com/chamilo/chamilo-lms/releases/tag/v2.0.1","label":"security-advisories@github.com"},{"url":"https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-g4c3-4g96-6g4m","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-g4c3-4g96-6g4m"}],"tags":["nvd","cve.org","ghsa","composer","exploit-available"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"total","timestamp":"2026-09-18T17:32:38.016494Z"},"epss":0.00976,"epssPercentile":0.60112,"aliases":["GHSA-g4c3-4g96-6g4m"],"ecosystem":"composer","ingestedAt":"2026-09-17T20:28:02.780Z","exploits":{"github":1,"githubRepos":["https://github.com/abraxas/CVE-2026-45140"],"checkedAt":"2026-09-21T15:29:05.844Z"},"exploitAvailable":true,"slug":"CVE-2026-45140","body":"## Overview\n\nChamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory does not identify the affected endpoint, component, input, or exploitation mechanism. This issue is fixed in version 2.0.1.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-45140)\n\nAffected packages:\n\n- `chamilo/chamilo-lms <= 2.0.0`\n\nPatched in:\n\n- `chamilo/chamilo-lms 2.0.1`\n\nSource: https://github.com/advisories/GHSA-g4c3-4g96-6g4m","depth":"abyssal","depthScore":66,"depthScoreParts":{"impact":53.9,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[{"seq":207751,"id":"CVE-2026-45140","ts":1789836691678,"field":"exploit_available","old":"false","new":"true"}]}