CVE-2026-102585
Received Received - Intake

Unauthorized Group Enrollment in Moodle

Vulnerability report for CVE-2026-102585, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Fedora Project

Description

A flaw was found in Moodle. When enrolling a user into a course while assigning them to a group, the application does not verify whether the selected group actually belongs to that course. An authenticated user with teacher privileges could exploit this flaw to add users to groups within courses they do not have authorization to access.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
moodle moodle *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-842 The product or the administrator places a user into an incorrect group.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Moodle, a learning management system. When a teacher enrolls a user into a course and assigns them to a group, Moodle does not check if the group actually belongs to that course. This allows teachers to add users to groups in courses they are not authorized to access.

Detection Guidance

To detect this vulnerability, review Moodle logs for unauthorized group enrollments. Check for teacher accounts enrolling users into groups outside their course permissions. Look for suspicious activity in the 'course enrolment' and 'group assignment' logs.

Impact Analysis

If you are a teacher or admin in Moodle, an attacker with teacher privileges could exploit this to add users to unauthorized groups. This could lead to unauthorized access to course materials or sensitive information within those groups.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR or HIPAA. Unauthorized group access could expose personal or health information, resulting in legal and regulatory penalties.

Mitigation Strategies

Update Moodle to the latest version to patch this flaw. Review and restrict teacher permissions to ensure they can only assign users to groups within their authorized courses. Monitor group enrollment activities for anomalies.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102585. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart