CVE-2026-1106 | Chamilo LMS up to 2.0.0 Beta 1 Legal Consent SocialController.php deleteLegal userId improper authorization (EUVD-2026-3191 / CNNVD-202601-2972)
A vulnerability classified as critical has been found in Chamilo LMS up to 2.0.0 Beta 1. This issue affects the function deleteLegal of the file src/CoreBundle/Controller/SocialController.php of the component Legal Consent Handler. Performing a manipulation of the argument userId results in improper authorization.
This vulnerability is reported as CVE-2026-1106. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.