4.3

CVE-2026-102584

Moodle: missing capability check allows unauthorised grade penalty recalculation

A flaw was found in Moodle. Due to a missing capability check, a low-privileged authenticated user can trigger the recalculation of grade penalties without holding the required permissions. This issue allows unauthorized users to modify grade penalty records, potentially altering student assessment scores.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Moodle ≫ Moodle Version >= 5.0.0 < 5.0.9
Moodle ≫ Moodle Version >= 5.1.0 < 5.1.6
Moodle ≫ Moodle Version >= 5.2.0 < 5.2.2
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.084
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
patrick@puiterwijk.org 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CWE-425 Direct Request ('Forced Browsing')

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

https://moodle.org/mod/forum/discuss.php?d=482502
Vendor Advisory
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-88585
Patch
https://access.redhat.com/security/cve/CVE-2026-102584
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2543637
Third Party Advisory
Issue Tracking