UBUNTU-CVE-2026-102587

Source
https://ubuntu.com/security/CVE-2026-102587
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-102587.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-102587
Upstream
  • CVE-2026-102587
Published
2026-09-30T09:17:00Z
Modified
2026-10-01T00:21:06Z
Severity
  • 2.7 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

A flaw was found in Moodle. User list filters do not properly enforce visibility restrictions on user profile fields. An authorized user with manager privileges can filter user lists using profile attributes they are not permitted to view directly, resulting in unauthorized information disclosure by inferring hidden user data.

References

Affected packages

Ubuntu:Pro:16.04:LTS / moodle

Package

Name
moodle
Purl
pkg:deb/ubuntu/moodle?arch=source&distro=esm-apps-legacy%2Fxenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.7.9+dfsg-1
2.7.10+dfsg-1
2.7.11+dfsg-1
2.7.11+dfsg-2
2.7.12+dfsg-1
3.*
3.0.3+dfsg-0ubuntu1
3.0.3+dfsg-0ubuntu1+esm1

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "moodle",
            "binary_version":  "3.0.3+dfsg-0ubuntu1+esm1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-102587.json"

Ubuntu:Pro:18.04:LTS / moodle

Package

Name
moodle
Purl
pkg:deb/ubuntu/moodle?arch=source&distro=esm-apps%2Fbionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.0.3+dfsg-0ubuntu1
3.0.3+dfsg-0ubuntu1+esm1

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "moodle",
            "binary_version":  "3.0.3+dfsg-0ubuntu1+esm1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-102587.json"