REDHAT-BUG-2543637: Medium severity Moodle Moodle vulnerability
Published Sep 29, 2026
·Updated
A flaw was found in Moodle. Missing capability checks made it possible for a low-privileged authenticated user to trigger grade penalty recalculation without holding the capability normally required to do so.
Affected Software
1 affected component
Moodle Moodle
Event History
Sep 29, 2026
Data Sourced
via Red Hat·08:36 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What level of access does an attacker need?
An attacker must be an authenticated Moodle user with low privileges. The flaw does not indicate that unauthenticated users can exploit it.
2
What action can an affected user perform?
A low-privileged authenticated user can trigger grade penalty recalculation despite lacking the capability normally required for that action.