CVE-2026-102587: Moodle: user list filters bypass profile field visibility
A flaw was found in Moodle. User list filters did not respect user profile field visibility settings, allowing a manager to filter by a profile field they could not otherwise view on a user's profile, resulting in partial, inference-based information disclosure.
Other sources
A flaw was found in Moodle. User list filters do not properly enforce visibility restrictions on user profile fields. An authorized user with manager privileges can filter user lists using profile attributes they are not permitted to view directly, resulting in unauthorized information disclosure by inferring hidden user data.
— MITRE
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authorized user with manager privileges can exploit it. The attacker must be able to use user-list filtering; unauthenticated users are not described as affected.
What information can be exposed?
The issue can disclose partial information about profile-field values that the manager is not permitted to view directly. Disclosure occurs through inference from the results of filtering user lists.
Does exploitation require user interaction or special conditions?
No user interaction is required. The provided vector indicates network access, low attack complexity, and high privileges required.
How can an organization identify potential exposure?
Review whether manager-role users can filter user lists by profile fields whose visibility settings prevent those users from viewing the fields on individual profiles. Such filtering may allow hidden values to be inferred from matching list results.