Sceawere

Vulnerability Detail

CVE-2026-102579UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Moodle Grade Web Service Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
3h ago
Vendor
—
Product
N/A
Attack Type
Exposure of Private Personal Information to an Unauthorized Actor
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

A flaw was found in Moodle. An incorrect capability check in the grade web service allows an authenticated student to access profile information of other students enrolled in the same course that they should not have permission to view. This issue leads to unauthorized information disclosure.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-09-30T09:17:14.947Z",
  "pubdate": "2026-09-30T09:17:14.947Z",
  "executiveSummary": "An incorrect capability check vulnerability has been identified within the Moodle grade web service. This flaw constitutes an Improper Authorization vulnerability, enabling an authenticated student to bypass intended access controls.\nThe vulnerability allows an authenticated user, typically a student, to retrieve sensitive profile information belonging to other students within the same shared course. Under normal operational parameters, these users should not possess the requisite permissions to view such data.\nThe impact of this disclosure includes the unauthorized exposure of personally identifiable information (PII) or student metadata. The vulnerability exists within the Moodle framework, specifically affecting its web service infrastructure.\nExploitation requires the attacker to have an active authenticated session within the target Moodle instance and enrollment in at least one course shared with the victim. This is a privilege escalation and information disclosure issue that compromises the confidentiality of user data stored within the platform.",
  "technicalDetails": "The vulnerability originates from a flawed implementation of the capability check mechanism within the Moodle grade web service. Specifically, when the system processes requests related to student grading or course participation, it fails to adequately validate if the requesting user possesses the correct 'moodle/user:viewdetails' or equivalent capability contextually required for the requested profile data.\nThe root cause is a deficiency in the access control logic governing the API endpoints responsible for serving student information. In Moodle's architecture, web services leverage specific capability checks to ensure that the requester is authorized to access the requested resource. In this instance, the logic incorrectly assumes that course-level enrollment implicitly grants access to other participants' profile details, ignoring the standard security constraints defined by the site administrator or system role definitions.\nThe attack flow proceeds as follows: First, the attacker authenticates to the Moodle application using a standard student account. Second, the attacker identifies the web service endpoint associated with the grade or student information retrieval process. Third, the attacker initiates a request to the web service, targeting the user ID of a peer enrolled in the same course. Fourth, because the capability check is improperly implemented, the backend service fails to enforce the 'capability' requirements, erroneously validating the request based solely on shared enrollment status. Finally, the server returns the profile details of the target student to the attacker, bypassing the site's privacy settings.\nThis vulnerability is classified as an authorization bypass. The exploitable component is the Moodle core grade web service. Authentication is a requirement, as the attacker must be a registered user within the system. The exposure is network-based, reachable through the web service interface that the Moodle installation provides. The impact of successful exploitation is a direct unauthorized disclosure of user profile information, which may include details that users expected to remain private, such as contact information, activity logs, or other meta-data accessible through the profile view."
}
CVE-2026-102579: Moodle Grade Web Service Information Disclosure (MEDIUM Severity, CVSS: 4.3) | Sceawere