User Data Exposure in Moodle Due to Insufficient Visibility Constraints
CVE-2026-102587
2.7LOW
What is CVE-2026-102587?
A flaw exists in Moodle where user list filters fail to enforce proper visibility restrictions on user profile fields. An authorized user with manager privileges has the capability to filter user lists using profile attributes that should remain hidden. This can lead to unauthorized disclosure of sensitive user information, allowing the manager to infer hidden data about users, potentially compromising privacy and security.
References
CVSS V3.1
Score:
2.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Upstream acknowledges Martin Greenaway as the original reporter.
