REDHAT-BUG-2543633: Medium severity Moodle Moodle vulnerability
Published Sep 29, 2026
·Updated
A flaw was found in Moodle's grade web service. An incorrect capability check allowed a student to access profile information of other students enrolled in the same course, which they would not otherwise have access to.
Affected Software
1 affected component
Moodle Moodle
Event History
Sep 29, 2026
Data Sourced
via Red Hat·08:35 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
Who can access the exposed information?
A student enrolled in a course can access profile information belonging to other students enrolled in that same course.
2
What access does an attacker need to exploit this issue?
The attacker needs a student account and enrollment in the same course as the students whose profile information they want to access.
3
Is the issue limited to a particular Moodle component?
The flaw is in Moodle's grade web service, where an incorrect capability check permits the unauthorized profile-information access.