Chamilo LMS versions prior to 1.11.38 and 2.0.0-RC.3 use a weak password reset mechanism that generates tokens using sha1($email) with no random component, no expiration, and no rate limiting. An attacker who knows a user's email can compute the reset token and change the victim's password without authentication.
An unauthenticated attacker can hijack any user account in affected Chamilo LMS installations by computing the predictable password reset token using only the target's email address. This enables complete account takeover with high confidentiality and integrity impact, allowing attackers to access sensitive learning data, modify course content, impersonate users, and disrupt the learning environment.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
Patches are available. Upgrade to Chamilo LMS version 1.11.38 or 2.0.0-RC.3 or later.
Immediately upgrade Chamilo LMS installations to version 1.11.38 or 2.0.0-RC.3 or later. Prioritize patching based on the exposure and number of users in your Chamilo LMS environment. Monitor account access logs for suspicious password reset activities. Consider restricting email visibility and implementing additional authentication mechanisms in the interim if patching cannot be completed immediately.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
NVD published the first details for CVE-2026-33707
A CVSS base score of 9.4 has been assigned.
Feedly found the first article mentioning CVE-2026-33707 . See article
CVE-2026-33707 is a critical vulnerability in Chamilo LMS, with a CVSS score of 9.4, allowing unauthenticated attackers to exploit predictable password reset token generation to take over user accounts. While no public proof-of-concept exploits are available, the vulnerability affects versions prior to 1.11.38 and 2.0.0-RC.3, and it can be mitigated by updating to these versions or newer. There is no mention of exploitation in the wild or downstream impacts on third-party vendors. See article
CVE-2026-33707 - Exploits & Severity - Feedly
Chamilo LMS Critical OS Command Injection
Chamilo LMS Predictable Password Reset Leads to Account Takeover (CVE-2026-33707)
CVE-2026-33707 - Exploits & Severity - Feedly
Chamilo LMS PHP eval() RCE
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
