Manual Enrolment Management Flaw in Moodle by Moodle HQ
CVE-2026-102582

2.2LOW

Key Information:

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-102582?

A security flaw exists in Moodle, specifically on the manual enrolment management page. The issue arises from inadequate checks that fail to verify whether the manual enrolment plugin is disabled, which could allow users with enrolment permissions to access this page directly via its URL. As a result, an authorized user may regain the ability to manage manual enrolments, undermining the administrator's controls even if the feature has been disabled within the user interface.

References

CVSS V3.1

Score:
2.2
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Upstream acknowledges Paul Holden as the original reporter.
.