CVE-2026-102585

Source
https://cve.org/CVERecord?id=CVE-2026-102585
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102585.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-102585
Aliases
Downstream
Published
2026-09-30T08:36:17Z
Modified
2026-10-05T14:41:05Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Moodle: group validation missing when enrolling user to course
Details

A flaw was found in Moodle. When enrolling a user into a course while assigning them to a group, the application does not verify whether the selected group actually belongs to that course. An authenticated user with teacher privileges could exploit this flaw to add users to groups within courses they do not have authorization to access.

Database specific
{
    "cna_assigner":  "fedora",
    "cwe_ids":  [
        "CWE-842"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102585.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "introduced":  "5.2.0"
                },
                {
                    "fixed":  "5.2.2"
                },
                {
                    "introduced":  "5.1.0"
                },
                {
                    "fixed":  "5.1.6"
                }
            ],
            "source":  "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/moodle/moodle

Affected ranges

Type
GIT
Repo
https://github.com/moodle/moodle
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "5.1.0"
        },
        {
            "fixed":  "5.1.6"
        },
        {
            "introduced":  "5.2.0"
        },
        {
            "fixed":  "5.2.2"
        }
    ],
    "source":  "CPE_RANGE"
}

Affected versions

v5.*
v5.1.0
v5.1.1
v5.1.2
v5.1.3
v5.1.4
v5.1.5
v5.2.0
v5.2.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102585.json"