Skip to content
Critical XSS Vulnerability in Chamilo LMS Leads to Admin Account Takeover

Critical XSS Vulnerability in Chamilo LMS Leads to Admin Account Takeover

First seen 21 Jul 2026, 09:36 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 22, 2026 at 06:39 UTC
  • CVE-2026-39878 allows unauthenticated attackers to take over admin accounts in Chamilo LMS.
  • The vulnerability affects Chamilo LMS versions 1.11.38 and earlier, with a CVSS score of 9.3.
  • A patch is available in version 1.11.40; users are urged to update immediately.

A critical stored cross-site scripting vulnerability, CVE-2026-39878, was discovered in Chamilo LMS versions 1.11.38 and earlier. This flaw allows unauthenticated attackers to execute arbitrary JavaScript in an administrator's browser session, potentially leading to a full platform admin account takeover. The vulnerability was published on July 20, 2026, and has a CVSS score of 9.3, indicating a high severity level. A patch has been released in version 1.11.40 to address this issue. Users of affected versions are urged to update immediately to mitigate the risk. The vulnerability is linked to CWE-79, highlighting improper input neutralization during web page generation. Public exploits for this vulnerability are already available, raising concerns about potential widespread exploitation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 52d ago How this analysis works

Timeline

2026-07-18
CVE-2026-16155 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-20
CVE-2026-39878 published
Chamilo LMS vulnerability allows admin account takeover via stored XSS in user registration.
cvefeed.io
2026-07-20
Patch released for Chamilo LMS
Version 1.11.40 released to address CVE-2026-39878 vulnerability.
cvefeed.io
2026-07-21
Exploits for CVE-2026-39878 found
Public exploits for the Chamilo LMS vulnerability are available, increasing risk of exploitation.
Feedly

More articles in this cluster (6)

Following this threat?

Track CVE-2026-16155 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed