CVE-2026-102584: Moodle: missing capability check allows unauthorised grade penalty recalculation
A flaw was found in Moodle. Due to a missing capability check, a low-privileged authenticated user can trigger the recalculation of grade penalties without holding the required permissions. This issue allows unauthorized users to modify grade penalty records, potentially altering student assessment scores.
Other sources
A flaw was found in Moodle. Missing capability checks made it possible for a low-privileged authenticated user to trigger grade penalty recalculation without holding the capability normally required to do so.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need?
An attacker must be an authenticated Moodle user with low privileges. No user interaction is required, and the attacker does not need the capability that normally permits grade penalty recalculation.
What can an attacker change through this issue?
The attacker can trigger recalculation of grade penalties and thereby modify grade penalty records. This can potentially alter student assessment scores; the reported impact is limited to integrity.
Which environments are most exposed?
Moodle environments are exposed where low-privileged authenticated users can reach the grade penalty recalculation functionality despite lacking its required capability. The provided information does not identify affected versions or state whether a default configuration is affected.