CVE-2026-102580

Published: Set 30, 2026 Last Modified: Set 30, 2026
ExploitDB:
Other exploit source:
Google Dorks:
LOW 2,2
Attack Vector: network
Attack Complexity: high
Privileges Required: high
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: low
Availability: none

Description

AI Translation Available

A flaw was found in Moodle. An authenticated attacker can supply an improperly validated audience class name to the Report Builder component, allowing arbitrary class instantiation. This vulnerability enables the unauthorized creation of internal program objects, which may result in unexpected application behavior.

470

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

Draft
Common Consequences
Security Scopes Affected:
Integrity Confidentiality Availability Other
Potential Impacts:
Execute Unauthorized Code Or Commands Alter Execution Logic Dos: Crash, Exit, Or Restart Other Read Application Data
Applicable Platforms
Languages: Java, PHP, Interpreted
View CWE Details
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-89078
https://access.redhat.com/security/cve/CVE-2026-102580
https://bugzilla.redhat.com/show_bug.cgi?id=2543635
https://moodle.org/mod/forum/discuss.php?d=482498