CVE-2026-102585

Published: Set 30, 2026 Last Modified: Set 30, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 4,3
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: low
Availability: none

Description

AI Translation Available

A flaw was found in Moodle. When enrolling a user into a course while assigning them to a group, the application does not verify whether the selected group actually belongs to that course. An authenticated user with teacher privileges could exploit this flaw to add users to groups within courses they do not have authorization to access.

842

Placement of User into Incorrect Group

Incomplete
Common Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Gain Privileges Or Assume Identity
Applicable Platforms
All platforms may be affected
View CWE Details
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-88538
https://access.redhat.com/security/cve/CVE-2026-102585
https://bugzilla.redhat.com/show_bug.cgi?id=2543639
https://moodle.org/mod/forum/discuss.php?d=482503