CVE-2026-102580
Received Received - Intake

Authenticated Object Injection in Moodle Report Builder

Vulnerability report for CVE-2026-102580, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Fedora Project

Description

A flaw was found in Moodle. An authenticated attacker can supply an improperly validated audience class name to the Report Builder component, allowing arbitrary class instantiation. This vulnerability enables the unauthorized creation of internal program objects, which may result in unexpected application behavior.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
moodle moodle *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-470 The product uses external input with reflection to select which classes or code to use, but it does not sufficiently prevent the input from selecting improper classes or code.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Moodle's Report Builder component. An authenticated attacker can provide a class name that isn't properly validated, allowing them to create instances of any class within the application. This could lead to unexpected behavior but does not currently have a known path to stronger attacks like code execution.

Detection Guidance

Detecting this vulnerability requires checking Moodle's Report Builder component for improperly validated audience class names. Review logs for suspicious class instantiation attempts in core_reportbuilder. Look for unusual application behavior like unexpected object creation or runtime errors. No specific commands are provided in the resources, but monitoring for arbitrary class instantiation in logs is recommended.

Impact Analysis

The impact is limited. It allows unauthorized creation of internal objects which may cause unexpected app behavior. No confirmed cases of data disclosure or code execution exist. The severity is low, and exploitation requires authentication.

Compliance Impact

The vulnerability allows arbitrary class instantiation in Moodle's Report Builder component, which could lead to unauthorized program behavior. However, no confirmed cases of data disclosure or code execution have been identified. This limits direct impact on compliance with standards like GDPR or HIPAA, which focus on data protection and unauthorized access. The low severity and lack of exploitable gadget chains reduce immediate compliance risks.

Mitigation Strategies

Update Moodle to the latest version to ensure the Report Builder component has proper input validation for audience class names. Monitor application logs for unusual class instantiation events or unexpected application behavior.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102580. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart