Unauthorized Access Flaw in Moodle's AI Image Generation Feature
CVE-2026-102583

2.7LOW

Key Information:

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-102583?

A vulnerability exists in Moodle whereby an insufficient capability check in the AI editor's image generation web service permits authenticated users to engage the feature without possessing the necessary permissions. This flaw exposes the AI image generation capabilities to unauthorized users, allowing them to generate images even if they do not hold the required access rights. Organizations using affected versions of Moodle should review their security settings and apply necessary updates to safeguard against unauthorized exploits.

References

CVSS V3.1

Score:
2.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Upstream acknowledges Paul Holden as the original reporter.
.