Critical XSS Vulnerability in Chamilo LMS Leads to Admin Account Takeover
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A critical stored cross-site scripting vulnerability, CVE-2026-39878, was discovered in Chamilo LMS versions 1.11.38 and earlier. This flaw allows unauthenticated attackers to execute arbitrary JavaScript in an administrator's browser session, potentially leading to a full platform admin account takeover. The vulnerability was published on July 20, 2026, and has a CVSS score of 9.3, indicating a high severity level. A patch has been released in version 1.11.40 to address this issue. Users of affected versions are urged to update immediately to mitigate the risk. The vulnerability is linked to CWE-79, highlighting improper input neutralization during web page generation. Public exploits for this vulnerability are already available, raising concerns about potential widespread exploitation.
Key Points: • CVE-2026-39878 allows unauthenticated attackers to take over admin accounts in Chamilo LMS. • The vulnerability affects Chamilo LMS versions 1.11.38 and earlier, with a CVSS score of 9.3. • A patch is available in version 1.11.40; users are urged to update immediately.