Arbitrary Class Instantiation Vulnerability in Moodle by Moodle Community
CVE-2026-102580

2.2LOW

Key Information:

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-102580?

A vulnerability in Moodle enables an authenticated attacker to supply an improperly validated audience class name to the Report Builder component, leading to arbitrary class instantiation. This flaw allows for the unauthorized creation of internal program objects, potentially resulting in unexpected application behavior and impacting the integrity of the Moodle environment. It underscores the importance of rigorous input validation and security measures in ensuring stable and secure application performance.

References

CVSS V3.1

Score:
2.2
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Upstream acknowledges Paul Holden as the original reporter.
.