4.3

CVE-2026-102580

Moodle: arbitrary class instantiation via report builder audience classname

A flaw was found in Moodle. An authenticated attacker can supply an improperly validated audience class name to the Report Builder component, allowing arbitrary class instantiation. This vulnerability enables the unauthorized creation of internal program objects, which may result in unexpected application behavior.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Moodle ≫ Moodle Version < 4.5.13
Moodle ≫ Moodle Version >= 5.0.0 < 5.0.9
Moodle ≫ Moodle Version >= 5.1.0 < 5.1.6
Moodle ≫ Moodle Version >= 5.2.0 < 5.2.2
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.23% 0.128
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
patrick@puiterwijk.org 2.2 0.7 1.4
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
CWE-470 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

The product uses external input with reflection to select which classes or code to use, but it does not sufficiently prevent the input from selecting improper classes or code.

https://moodle.org/mod/forum/discuss.php?d=482498
Vendor Advisory
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-89078
Patch
https://access.redhat.com/security/cve/CVE-2026-102580
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2543635
Third Party Advisory
Issue Tracking