Unauthorized Access Flaw in Moodle's AI Image Generation Feature
CVE-2026-102583
2.7LOW
What is CVE-2026-102583?
A vulnerability exists in Moodle whereby an insufficient capability check in the AI editor's image generation web service permits authenticated users to engage the feature without possessing the necessary permissions. This flaw exposes the AI image generation capabilities to unauthorized users, allowing them to generate images even if they do not hold the required access rights. Organizations using affected versions of Moodle should review their security settings and apply necessary updates to safeguard against unauthorized exploits.
References
CVSS V3.1
Score:
2.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Upstream acknowledges Paul Holden as the original reporter.
