CVE-2026-102580
LOW
2,2
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: high
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: low
Availability: none
Description
AI Translation Available
A flaw was found in Moodle. An authenticated attacker can supply an improperly validated audience class name to the Report Builder component, allowing arbitrary class instantiation. This vulnerability enables the unauthorized creation of internal program objects, which may result in unexpected application behavior.
470
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
DraftCommon Consequences
Security Scopes Affected:
Integrity
Confidentiality
Availability
Other
Potential Impacts:
Execute Unauthorized Code Or Commands
Alter Execution Logic
Dos: Crash, Exit, Or Restart
Other
Read Application Data
Applicable Platforms
Languages:
Java, PHP, Interpreted
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-89078
https://access.redhat.com/security/cve/CVE-2026-102580
https://bugzilla.redhat.com/show_bug.cgi?id=2543635
https://moodle.org/mod/forum/discuss.php?d=482498