CVE-2026-33706 | Chamilo LMS up to 1.11.37 update_user_from_username Status privileges management (GHSA-3gqc-xr75-pcpw)
A vulnerability classified as critical has been found in Chamilo LMS up to 1.11.37. Affected by this issue is the function update_user_from_username. This manipulation of the argument Status causes improper privilege management.
The identification of this vulnerability is CVE-2026-33706. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.