Information Disclosure Vulnerability in Moodle by Moodle Pty Ltd
CVE-2026-102579
4.3MEDIUM
What is CVE-2026-102579?
A flaw in Moodle's grade web service misconfigures capability checks, enabling authenticated students to access sensitive profile information of their peers enrolled in the same course, which they should not have permission to view. This vulnerability poses a serious risk of unauthorized information disclosure, undermining user privacy and data security.
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Upstream acknowledges Itamarperetz2c7cc5 as the original reporter.
