CVE-2026-32894 | Chamilo LMS up to 1.11.37/2.0.0-RC.2 delete_mark/resultdelete null pointer dereference (GHSA-rqpg-p95v-fv98)
A vulnerability described as problematic has been identified in Chamilo LMS up to 1.11.37/2.0.0-RC.2. Impacted is an unknown function. Such manipulation of the argument delete_mark/resultdelete leads to null pointer dereference.
This vulnerability is referenced as CVE-2026-32894. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.