Arbitrary Class Instantiation Vulnerability in Moodle by Moodle Community
CVE-2026-102580
2.2LOW
What is CVE-2026-102580?
A vulnerability in Moodle enables an authenticated attacker to supply an improperly validated audience class name to the Report Builder component, leading to arbitrary class instantiation. This flaw allows for the unauthorized creation of internal program objects, potentially resulting in unexpected application behavior and impacting the integrity of the Moodle environment. It underscores the importance of rigorous input validation and security measures in ensuring stable and secure application performance.
References
CVSS V3.1
Score:
2.2
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Upstream acknowledges Paul Holden as the original reporter.
