CVE-2026-32931

Chamilo LMS has Arbitrary File Upload via MIME-Only Validation in Exercise Sound Upload Leads to RCE

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an unrestricted file upload vulnerability in the exercise sound upload function allows an authenticated teacher to upload a PHP webshell by spoofing the Content-Type header to audio/mpeg. The uploaded file retains its original .php extension and is placed in a web-accessible directory, enabling Remote Code Execution as the web server user (www-data). This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3.


We have discovered 10 live websites that are affected by CVE-2026-32931.

Run a Free Instant Scan




Affected Software

Product  Chamilo
Category Learning Management System
Vulnerable Domains10 live websites (83% of Chamilo install base)
Vulnerable Versions
  • from 0 through 1.11.38
  • from 2 through 2
Vulnerable Versions Count3 versions ( 75% of all versions)


Common Weakness Enumeration

CWE-434 Unrestricted Upload of File with Dangerous Type



Details

  • Published - Apr 10, 2026
  • Updated - Apr 15, 2026

Website Distribution by Country

Number of websites using CVE-2026-32931
United States3 websites



Spain2 websites
France2 websites
Italy1 websites
Netherlands1 websites
Peru1 websites

Website Distribution by TLD

Number of websites using CVE-2026-32931
.com4 websites
.net1 websites
.nl1 websites
.org1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-32931

Top websites that are affected by CVE-2026-32931. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**.******.gt United States*,***,***
**************.net Italy**,***,***
*****.******.nl Netherlands**,***,***
**************.com United States**,***,***
****.**********.com United States**,***,***
*************.****************.org France**,***,***
******.**************.com France**,***,***
****.******.***.pe Peru**,***,***
***************.com Spain***,***,***
************.***.es Spain***,***,***
See full domain list

FAQ

CVE-2026-32931 is Unrestricted Upload of File with Dangerous Type in Chamilo
A total of 10 websites have been identified as vulnerable to CVE-2026-32931, based on global website indexing conducted by WebTechSurvey.
The Chamilo is affected by the CVE-2026-32931 vulnerability.
Chamilo versions up to 2 are vulnerable to CVE-2026-32931.
CVE-2026-32931 is resolved in version 2 of Chamilo.