CVE-2026-54733

Source
https://cve.org/CVERecord?id=CVE-2026-54733
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54733.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-54733
Aliases
  • GHSA-hqjh-93qv-47v5
Published
2026-07-16T14:52:03.389Z
Modified
2026-07-18T03:47:38.338112792Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
moodle-local_o365: Authentication bypass via unverified JWT signature in Teams SSO endpoint
Details

The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0.5, and 5.1.1, the Microsoft Office 365 Integration plugin localo365 Teams SSO endpoint ssologin.php base64-decodes a JWT payload and authenticates users from the upn claim without verifying the JWT signature, allowing an unauthenticated attacker to forge a token and obtain a Moodle session as an O365-authenticated user. This issue is fixed in versions 4.5.6, 5.0.5, and 5.1.1.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54733.json",
    "cwe_ids": [
        "CWE-347"
    ],
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/microsoft/o365-moodle

Affected ranges

Type
GIT
Repo
https://github.com/microsoft/o365-moodle
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "4.5.6"
        },
        {
            "introduced": "5.0.0"
        },
        {
            "fixed": "5.0.5"
        },
        {
            "introduced": "5.1.0"
        },
        {
            "fixed": "5.1.1"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v1.*
v1.0.0.0
Other
v20150310_m28
v20150316_m28
v20150324_m28
v20150327_m28
v20150421_m28
v20150504_m28
v20150519_m28
v20150601_m28
v20150601_m29
v20150804_m29
v20150928_m29
v20151019_m29
v20151116_m29
v20151130_m30
v20151214_m30
v20160119_m30
v20160201_m30
v20160216_m30
v20160229_m30
v20160328_m30
v20160411_m30
v20160425_m30
v20160526_30
v20160526_m30
v20160620_m30
v20160718_m31
v20160721_m31
v20160725_m31
v20160804_m31
v20160831_m31
v20161111_m31
v20161202_m31
v20170116_m31
v20170116_m32
v20170511_m32
v20170627_m32
v20171031_m32
v20171031_m33
v20180129_m34
v20180430_m34
v20180625_m35
v20181105_m35
v20190119_m35
v20190416_m36
v20190729_m37
v20191007_m37
v20191108_m37
v20200128_m37
v20200309_m38
v20200313_m38
v20200515_m38
v20200716_m39
v20200929_m39
v20201118_m39
v20201123_m39
v20210128_m310
v20210326_m310
v20210629_m310
v20210702_m310
v20210901_m311
v20211026_m311
v20211026_v311
v20211207_m311
v20220406_m311
v20220407_m311
v20220408_m311
v20220411_m311
v20220512_m40
v20220621_m40
v20221006_m40
v20221012_m40
v20221128_m41
v20230228_m401
v20230525_m402
v20230628_m402
v20231010_m402
v20231218_m403
v20240311_m403
v20240313_m403
v20240412_m403
v20240702_m403
v20240703_m403
v20240722_m404
v20241017_m404
v20241125_m405
v20250226_m405
v20250303_m405
v20250929_m500
v20251001_m500
v20251209_m405
v20251209_m500
v20251211_m405
v20251211_m500
v20251223_m405
v20251223_m500
v20260210_m501
v27.*
v27.0.0.1
v28.*
v28.0.0.0
v28.0.0.1
v3.*
v3.10.0
v3.10.1
v3.10.2
v3.10.3
v3.11.0
v3.11.1
v3.11.2
v3.11.3
v3.9.0
v3.9.1
v3.9.2
v4.*
v4.0.0
v4.0.1
v4.0.2
v4.1.0
v4.1.1
v4.2.0
v4.2.1
v4.2.2
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.5.0
v4.5.1
v4.5.2
v4.5.3
v4.5.4
v4.5.5
v5.*
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54733.json"