2.7

CVE-2026-102583

Moodle: incorrect capability check in ai generate image web service

A flaw was found in Moodle. An incorrect capability check in the artificial intelligence (AI) editor placement's image generation web service allows an authenticated user to invoke the feature without holding the required capability. This flaw permits unauthorized users to access and utilize the AI image generation functionality.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Moodle ≫ Moodle Version < 4.5.13
Moodle ≫ Moodle Version >= 5.0.0 < 5.0.9
Moodle ≫ Moodle Version >= 5.1.0 < 5.1.6
Moodle ≫ Moodle Version >= 5.2.0 < 5.2.2
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.24% 0.132
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
patrick@puiterwijk.org 2.7 1.2 1.4
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
CWE-425 Direct Request ('Forced Browsing')

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

https://moodle.org/mod/forum/discuss.php?d=482501
Vendor Advisory
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-88587
Patch
https://access.redhat.com/security/cve/CVE-2026-102583
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2543640
Third Party Advisory
Issue Tracking