User Data Exposure in Moodle Due to Insufficient Visibility Constraints
CVE-2026-102587

2.7LOW

Key Information:

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-102587?

A flaw exists in Moodle where user list filters fail to enforce proper visibility restrictions on user profile fields. An authorized user with manager privileges has the capability to filter user lists using profile attributes that should remain hidden. This can lead to unauthorized disclosure of sensitive user information, allowing the manager to infer hidden data about users, potentially compromising privacy and security.

References

CVSS V3.1

Score:
2.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Upstream acknowledges Martin Greenaway as the original reporter.
.