Critical XSS Vulnerability in Chamilo LMS Leads to Admin Account Takeover
Article Content
- •CVE-2026-39878 allows unauthenticated attackers to take over admin accounts in Chamilo LMS.
- •The vulnerability affects Chamilo LMS versions 1.11.38 and earlier, with a CVSS score of 9.3.
- •A patch is available in version 1.11.40; users are urged to update immediately.
A critical stored cross-site scripting vulnerability, CVE-2026-39878, was discovered in Chamilo LMS versions 1.11.38 and earlier. This flaw allows unauthenticated attackers to execute arbitrary JavaScript in an administrator's browser session, potentially leading to a full platform admin account takeover. The vulnerability was published on July 20, 2026, and has a CVSS score of 9.3, indicating a high severity level. A patch has been released in version 1.11.40 to address this issue. Users of affected versions are urged to update immediately to mitigate the risk. The vulnerability is linked to CWE-79, highlighting improper input neutralization during web page generation. Public exploits for this vulnerability are already available, raising concerns about potential widespread exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track CVE-2026-16155 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…