Skip to content
CVE-2026-33707 - Exploits & Severity

CVE-2026-33707 - Exploits & Severity

Feedly April 11, 2026

Chamilo LMS versions prior to 1.11.38 and 2.0.0-RC.3 use a weak password reset mechanism that generates tokens using sha1($email) with no random component, no expiration, and no rate limiting. An attacker who knows a user's email can compute the reset token and change the victim's password without authentication.

An unauthenticated attacker can hijack any user account in affected Chamilo LMS installations by computing the predictable password reset token using only the target's email address. This enables complete account takeover with high confidentiality and integrity impact, allowing attackers to access sensitive learning data, modify course content, impersonate users, and disrupt the learning environment.

There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.

Patches are available. Upgrade to Chamilo LMS version 1.11.38 or 2.0.0-RC.3 or later.

Immediately upgrade Chamilo LMS installations to version 1.11.38 or 2.0.0-RC.3 or later. Prioritize patching based on the exposure and number of users in your Chamilo LMS environment. Monitor account access logs for suspicious password reset activities. Consider restricting email visibility and implementing additional authentication mechanisms in the interim if patching cannot be completed immediately.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

NVD published the first details for CVE-2026-33707

A CVSS base score of 9.4 has been assigned.

Feedly found the first article mentioning CVE-2026-33707 . See article

CVE-2026-33707 is a critical vulnerability in Chamilo LMS, with a CVSS score of 9.4, allowing unauthenticated attackers to exploit predictable password reset token generation to take over user accounts. While no public proof-of-concept exploits are available, the vulnerability affects versions prior to 1.11.38 and 2.0.0-RC.3, and it can be mitigated by updating to these versions or newer. There is no mention of exploitation in the wild or downstream impacts on third-party vendors. See article

CVE-2026-33707 - Exploits & Severity - Feedly

Chamilo LMS Critical OS Command Injection

Chamilo LMS Predictable Password Reset Leads to Account Takeover (CVE-2026-33707)

CVE-2026-33707 - Exploits & Severity - Feedly

Chamilo LMS PHP eval() RCE

Collect, analyze, and vulnerability reports faster using AI

Extracted Entities

Attack Types (1)

Platforms (1)