{"id":"CVE-2026-45140","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-45140","summary":"Chamilo LMS CStudio upload flow allows unauthenticated remote code execution","details":"### Impact\nAbility to run arbitrary code on the server without authentication.","published":"2026-09-17T20:23:39Z","modified":"2026-09-17T20:45:05.328230281Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"chamilo/chamilo-lms","fixedVersion":"2.0.1"}],"fix":{"url":"https://github.com/chamilo/chamilo-lms/commit/4bdba1b9a8820bd70c0809317775d7f6eaa79844","label":"chamilo/chamilo-lms@4bdba1b"},"references":[{"type":"WEB","url":"https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-g4c3-4g96-6g4m"},{"type":"WEB","url":"https://github.com/chamilo/chamilo-lms/commit/4bdba1b9a8820bd70c0809317775d7f6eaa79844"},{"type":"PACKAGE","url":"https://github.com/chamilo/chamilo-lms"},{"type":"WEB","url":"https://github.com/chamilo/chamilo-lms/releases/tag/v2.0.1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-17T20:45:05.328230281Z"}}