CVE-2026-102584Medium· 4.3▾ SunlitA flaw was found in Moodle. Due to a missing capability check, a low-privileged authenticated user can trigger the recalculation of grade penalties without holding the required permissions. This issue allows unauthorized users to modify …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A flaw was found in Moodle. Due to a missing capability check, a low-privileged authenticated user can trigger the recalculation of grade penalties without holding the required permissions. This issue allows unauthorized users to modify grade penalty records, potentially altering student assessment scores.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102582Low· 2.2A flaw was found in Moodle
CVE-2026-102583Low· 2.7A flaw was found in Moodle
CVE-2026-102581Medium· 4.6A flaw was found in Moodle
CVE-2026-102579Medium· 4.3A flaw was found in Moodle
CVE-2026-102577Medium· 4.3A flaw was found in Moodle
CVE-2026-102578Medium· 5.5A flaw was found in Moodle