Critical XSS Vulnerability in Chamilo LMS Leads to Admin Account Takeover

Critical XSS Vulnerability in Chamilo LMS Leads to Admin Account Takeover

First seen 21 Jul 2026, 09:36 UTC SecablyFeedlythreatcluster.iocvefeed.iocve.report+2 88% similarity 74.0

Article Content

Browse articles
ThreatCluster

A critical stored cross-site scripting vulnerability, CVE-2026-39878, was discovered in Chamilo LMS versions 1.11.38 and earlier. This flaw allows unauthenticated attackers to execute arbitrary JavaScript in an administrator's browser session, potentially leading to a full platform admin account takeover. The vulnerability was published on July 20, 2026, and has a CVSS score of 9.3, indicating a high severity level. A patch has been released in version 1.11.40 to address this issue. Users of affected versions are urged to update immediately to mitigate the risk. The vulnerability is linked to CWE-79, highlighting improper input neutralization during web page generation. Public exploits for this vulnerability are already available, raising concerns about potential widespread exploitation.

Key Points: • CVE-2026-39878 allows unauthenticated attackers to take over admin accounts in Chamilo LMS. • The vulnerability affects Chamilo LMS versions 1.11.38 and earlier, with a CVSS score of 9.3. • A patch is available in version 1.11.40; users are urged to update immediately.

ThreatCluster AI

Timeline

2026-07-18
CVE-2026-16155 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-20
CVE-2026-39878 published
Chamilo LMS vulnerability allows admin account takeover via stored XSS in user registration.
cvefeed.io
2026-07-20
Patch released for Chamilo LMS
Version 1.11.40 released to address CVE-2026-39878 vulnerability.
cvefeed.io
2026-07-21
Exploits for CVE-2026-39878 found
Public exploits for the Chamilo LMS vulnerability are available, increasing risk of exploitation.
Feedly

Community

Browse all →