CVE Vulnerabilities

CVE-2026-102583

Direct Request ('Forced Browsing')

Published: Sep 30, 2026 | Modified: Oct 01, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A flaw was found in Moodle. An incorrect capability check in the artificial intelligence (AI) editor placements image generation web service allows an authenticated user to invoke the feature without holding the required capability. This flaw permits unauthorized users to access and utilize the AI image generation functionality.

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Affected Software

NameVendorStart VersionEnd Version
MoodleMoodle*4.5.13 (excluding)
MoodleMoodle5.0.0 (including)5.0.9 (excluding)
MoodleMoodle5.1.0 (including)5.1.6 (excluding)
MoodleMoodle5.2.0 (including)5.2.2 (excluding)

Potential Mitigations

References