CVE-2026-33710
HIGHChamilo LMS has Weak REST API Key Generation (Predictable)
Title source: cnaDescription
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, REST API keys are generated using md5(time() + (user_id * 5) - rand(10000, 10000)). The rand(10000, 10000) call always returns exactly 10000 (min == max), making the formula effectively md5(timestamp + user_id*5 - 10000). An attacker who knows a username and approximate key creation time can brute-force the API key. This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3.
Scores
CVSS v3
7.5
EPSS
0.0004
EPSS Percentile
12.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-330
Status
published
Products (4)
chamilo/chamilo-lms
< 1.11.38
chamilo/chamilo-lms
>= 2.0.0-alpha.1, < 2.0.0-RC.3
chamilo/chamilo_lms
2.0.0 alpha1 (10 CPE variants)
chamilo/chamilo_lms
< 1.11.38
Published
Apr 10, 2026
Tracked Since
Apr 11, 2026