REDHAT-BUG-2543640: Low severity Moodle Moodle vulnerability
Published Sep 29, 2026
·Updated
A flaw was found in Moodle. An incorrect capability check in the AI editor placement's "generate image" web service allowed a user to invoke that feature without holding the required capability. The advisory does not state the exact privilege level of an affected user; this draft assumes access is limited to users who already hold some content-editing role rather than a fully anonymous or lowest-privilege user.
Affected Software
1 affected component
Moodle Moodle
Event History
Sep 29, 2026
Data Sourced
via Red Hat·08:37 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
Which user accounts should be prioritized during triage?
The advisory does not specify the exact privilege level required. This draft assumes exposure is limited to users who already have a content-editing role, rather than anonymous or lowest-privilege accounts.
2
Does the available advisory confirm whether default Moodle deployments are affected?
No. It does not state whether the affected AI editor placement or its image-generation feature is enabled by default.