---
id: CVE-2026-102583
title: A flaw was found in Moodle
summary: >-
  A flaw was found in Moodle. An incorrect capability check in the artificial
  intelligence (AI) editor placement's image generation web service allows an
  authenticated user to invoke the feature without holding the required
  capability. Thi…
severity: low
cvss: 2.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-425
product: moodle
affected:
  - moodle >= 5.2.0 < 5.2.2
  - moodle >= 5.1.0 < 5.1.6
  - moodle >= 5.0.0 < 5.0.9
  - moodle < 4.5.13
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T09:17:15.493'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102583'
references:
  - url: >-
      http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-88587
    label: patrick@puiterwijk.org
  - url: 'https://access.redhat.com/security/cve/CVE-2026-102583'
    label: patrick@puiterwijk.org
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2543640'
    label: patrick@puiterwijk.org
  - url: 'https://moodle.org/mod/forum/discuss.php?d=482501'
    label: patrick@puiterwijk.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T09:00:29.908Z'
---

## Overview

A flaw was found in Moodle. An incorrect capability check in the artificial intelligence (AI) editor placement's image generation web service allows an authenticated user to invoke the feature without holding the required capability. This flaw permits unauthorized users to access and utilize the AI image generation functionality.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
