Manual Enrolment Management Flaw in Moodle by Moodle HQ
CVE-2026-102582
2.2LOW
What is CVE-2026-102582?
A security flaw exists in Moodle, specifically on the manual enrolment management page. The issue arises from inadequate checks that fail to verify whether the manual enrolment plugin is disabled, which could allow users with enrolment permissions to access this page directly via its URL. As a result, an authorized user may regain the ability to manage manual enrolments, undermining the administrator's controls even if the feature has been disabled within the user interface.
References
CVSS V3.1
Score:
2.2
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Upstream acknowledges Paul Holden as the original reporter.
