CVE-2025-26531: IDOR in badges allows disabling of arbitrary badges
Insufficient capability checks made it possible to disable badges a user does not have permission to access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.1.16 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.3.10 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.4.6 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.5.2
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26531?
CVE-2025-26531 has a medium severity due to insufficient capability checks allowing unauthorized badge modifications.
How do I fix CVE-2025-26531?
To fix CVE-2025-26531, upgrade to Moodle versions 4.1.16, 4.3.10, 4.4.6, or 4.5.2 or later.
What is affected by CVE-2025-26531?
CVE-2025-26531 affects Moodle versions prior to 4.1.16, 4.3.10, 4.4.6, and 4.5.2.
Who is impacted by CVE-2025-26531?
Users with inappropriate permissions may exploit CVE-2025-26531 to disable badges they do not have access to.
Is there a workaround for CVE-2025-26531?
Currently, the recommended action is to upgrade to the patched versions as no specific workarounds are provided.