CVE-2026-102579
4.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Summary
A flaw was found in Moodle. An incorrect capability check in the grade web service allows an authenticated student to access profile information of other students enrolled in the same course that they should not have permission to view. This issue leads to unauthorized information disclosure.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
5.2.0 < 5.2.2 | affected | ||
5.1.0 < 5.1.6 | affected | ||
5.0.0 < 5.0.9 | affected | ||
0 < 4.5.13 | affected |
Weaknesses
- CWE-359: Exposure of Private Personal Information to an Unauthorized Actor
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-89381
- https://access.redhat.com/security/cve/CVE-2026-102579
- https://bugzilla.redhat.com/show_bug.cgi?id=2543633
- https://moodle.org/mod/forum/discuss.php?d=482497
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.