BIT-moodle-2026-102585

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/moodle/BIT-moodle-2026-102585.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-moodle-2026-102585
Aliases
Published
2026-10-05T11:55:31Z
Modified
2026-10-05T14:30:02Z
Summary
Moodle: group validation missing when enrolling user to course
Details

A flaw was found in Moodle. When enrolling a user into a course while assigning them to a group, the application does not verify whether the selected group actually belongs to that course. An authenticated user with teacher privileges could exploit this flaw to add users to groups within courses they do not have authorization to access.

Database specific
{
    "cpes":  [
        "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*"
    ],
    "severity":  "Medium"
}
References

Affected packages

Bitnami / moodle

Package

Name
moodle
Purl
pkg:bitnami/moodle

Severity

  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
5.1.0
Fixed
5.1.6
Introduced
5.2.0
Fixed
5.2.2

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/moodle/BIT-moodle-2026-102585.json"