UBUNTU-CVE-2026-102582

Source
https://ubuntu.com/security/CVE-2026-102582
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-102582.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2026-102582
Upstream
  • CVE-2026-102582
Published
2026-09-30T09:17:00Z
Modified
2026-10-01T00:26:11Z
Severity
  • 2.2 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

A flaw was found in Moodle. The manual enrolment management page did not properly check whether the manual enrolment plugin was disabled, allowing users with enrolment permissions to access the page directly by navigating to its URL. Consequently, an authorized user could manage manual enrolments even after an administrator disabled the feature in the user interface.

References

Affected packages

Ubuntu:Pro:16.04:LTS / moodle

Package

Name
moodle
Purl
pkg:deb/ubuntu/moodle?arch=source&distro=esm-apps-legacy%2Fxenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.7.9+dfsg-1
2.7.10+dfsg-1
2.7.11+dfsg-1
2.7.11+dfsg-2
2.7.12+dfsg-1
3.*
3.0.3+dfsg-0ubuntu1
3.0.3+dfsg-0ubuntu1+esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "moodle",
            "binary_version": "3.0.3+dfsg-0ubuntu1+esm1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-102582.json"

Ubuntu:Pro:18.04:LTS / moodle

Package

Name
moodle
Purl
pkg:deb/ubuntu/moodle?arch=source&distro=esm-apps%2Fbionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.0.3+dfsg-0ubuntu1
3.0.3+dfsg-0ubuntu1+esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "moodle",
            "binary_version": "3.0.3+dfsg-0ubuntu1+esm1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-102582.json"