---
id: CVE-2026-45140
title: Chamilo LMS is an open-source learning management system
summary: >-
  Chamilo LMS is an open-source learning management system. Prior to 2.0.1,
  Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary
  code on the server. The authoritative advisory does not identify the affected
  endpoint, …
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
  - CWE-94
  - CWE-219
  - CWE-434
vendor: chamilo
product: chamilo-lms
affected:
  - chamilo-lms < 2.0.1
patched:
  - chamilo/chamilo-lms 2.0.1
published: '2026-09-17'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:25:27.050'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-45140'
references:
  - url: >-
      https://github.com/chamilo/chamilo-lms/commit/4bdba1b9a8820bd70c0809317775d7f6eaa79844
    label: security-advisories@github.com
  - url: 'https://github.com/chamilo/chamilo-lms/releases/tag/v2.0.1'
    label: security-advisories@github.com
  - url: >-
      https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-g4c3-4g96-6g4m
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-g4c3-4g96-6g4m'
tags:
  - nvd
  - exploit-available
  - cve.org
  - ghsa
  - composer
epss: 0.01326
epssPercentile: 0.69744
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/abraxas/CVE-2026-45140'
  checkedAt: '2026-09-24T21:53:34.699Z'
exploitAvailable: true
aliases:
  - GHSA-g4c3-4g96-6g4m
ecosystem: composer
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-18T17:32:38.016494Z'
ingestedAt: '2026-09-17T20:28:02.780Z'
---

## Overview

Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory does not identify the affected endpoint, component, input, or exploitation mechanism. This issue is fixed in version 2.0.1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-45140)

Affected packages:

- `chamilo/chamilo-lms <= 2.0.0`

Patched in:

- `chamilo/chamilo-lms 2.0.1`

Source: https://github.com/advisories/GHSA-g4c3-4g96-6g4m
