CVE-2026-102584
Received Received - Intake

Grade Penalty Recalculation in Moodle

Vulnerability report for CVE-2026-102584, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Fedora Project

Description

A flaw was found in Moodle. Due to a missing capability check, a low-privileged authenticated user can trigger the recalculation of grade penalties without holding the required permissions. This issue allows unauthorized users to modify grade penalty records, potentially altering student assessment scores.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
moodle moodle *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-425 The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Moodle allows a low-privileged authenticated user to trigger grade penalty recalculations without the required permissions due to a missing capability check. This bypasses normal access controls and could let unauthorized users modify grade penalty records, potentially altering student assessment scores.

Detection Guidance

To detect this vulnerability, review Moodle logs for unauthorized grade penalty recalculations. Check for users with low privileges performing actions typically restricted to higher roles. Look for repeated requests to grade recalculation endpoints without proper capability checks.

Impact Analysis

If exploited, this flaw could allow unauthorized changes to student grades, undermining academic integrity. For educators or institutions, it may lead to incorrect grading, disputes, and reputational damage. Users with low privileges could manipulate grades without detection.

Compliance Impact

This vulnerability could violate data integrity requirements in GDPR (accuracy of personal data) and HIPAA (integrity of health records). Unauthorized grade changes may lead to non-compliance, fines, or legal issues if student data is compromised or altered improperly.

Mitigation Strategies

Apply the latest Moodle security patches immediately. Review and update user roles to ensure only authorized users can trigger grade recalculations. Monitor grade records for unauthorized changes and restrict access to administrative functions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102584. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart