4.3

CVE-2026-102585

Moodle: group validation missing when enrolling user to course

A flaw was found in Moodle. When enrolling a user into a course while assigning them to a group, the application does not verify whether the selected group actually belongs to that course. An authenticated user with teacher privileges could exploit this flaw to add users to groups within courses they do not have authorization to access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Moodle ≫ Moodle Version >= 5.1.0 < 5.1.6
Moodle ≫ Moodle Version >= 5.2.0 < 5.2.2
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.084
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
patrick@puiterwijk.org 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CWE-842 Placement of User into Incorrect Group

The product or the administrator places a user into an incorrect group.

https://moodle.org/mod/forum/discuss.php?d=482503
Vendor Advisory
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-88538
Patch
https://access.redhat.com/security/cve/CVE-2026-102585
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2543639
Third Party Advisory
Issue Tracking