Sceawere

Vulnerability Detail

CVE-2026-102580UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Moodle Report Builder Object Injection

Vulnerability Metadata

Severity
Low
Score / CVSS
2.2
Creation Date
3h ago
Vendor
—
Product
N/A
Attack Type
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
Vector String
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

A flaw was found in Moodle. An authenticated attacker can supply an improperly validated audience class name to the Report Builder component, allowing arbitrary class instantiation. This vulnerability enables the unauthorized creation of internal program objects, which may result in unexpected application behavior.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "2.2",
  "pubDate": "2026-09-30T09:17:15.080Z",
  "pubdate": "2026-09-30T09:17:15.080Z",
  "executiveSummary": "This vulnerability involves an insecure deserialization-like flaw within the Moodle Report Builder component, classified as an arbitrary class instantiation vulnerability.\nAn authenticated attacker can influence the application's logic by injecting an improperly validated audience class name, which the system subsequently instantiates.\nThe primary impact of this flaw is the unauthorized creation of internal program objects, which can be leveraged to manipulate system state, disrupt application workflow, or potentially serve as a vector for further exploitation.\nThe vulnerability affects the Moodle Report Builder component and requires the attacker to be authenticated to the target Moodle instance.\nGiven the ability to manipulate internal objects, this represents a significant security concern, as it allows for the subversion of intended application logic, potentially leading to unauthorized data access or service disruption.\nThe risk is exacerbated by the flexibility of PHP's object-oriented features, which may allow for complex object manipulation if suitable 'gadget' classes exist within the codebase.\nSuccessful exploitation requires the attacker to have legitimate access to the platform and specific knowledge of the class hierarchy within the Moodle environment.",
  "technicalDetails": "The vulnerability resides in the Report Builder component of Moodle, specifically within the logic responsible for handling 'audience' configurations. The root cause is the failure to implement a strict allow-list or a secure factory pattern when instantiating classes based on user-supplied input.\nWhen a user interacts with the Report Builder, the application accepts a class name representing an audience definition. Because the application logic proceeds to instantiate the provided class name directly without verifying that it implements the required interfaces or belongs to an expected namespace, an authenticated attacker can trigger the instantiation of arbitrary classes existing within the Moodle autoloader.\nThe exploitation flow begins with an authenticated attacker identifying a request parameter that specifies the audience class. By modifying this parameter, the attacker can force the application to instantiate any object available in the current execution context. This mechanism operates similarly to an object injection vulnerability, where the instantiation itself can trigger side effects located in the object's constructor or magic methods such as __destruct, __wakeup, or __toString.\nThe attack is characterized by the following steps: 1) Identification of the vulnerable input parameter within the Report Builder interface; 2) Crafting a payload containing the namespace-qualified name of a sensitive class available in the Moodle environment; 3) Submission of the request containing the malicious class name; 4) Execution of the application code which instantiates the user-supplied class string; 5) Resulting side effects during object lifecycle management.\nWhile the specific impact is dependent on the classes available in the target version, the ability to instantiate internal objects allows an attacker to manipulate the application's runtime environment. This can result in unauthorized data exposure, bypass of access control checks, or the triggering of unexpected code paths that were not intended to be reachable by the authenticated user. Because the underlying issue is the lack of input validation on the class instantiation process, it represents a fundamental breakdown in the application's architectural security regarding reflection-like capabilities.\nThe vulnerability is limited by the set of classes present in the application's include path, as the attacker is restricted to classes known to the autoloader. However, in a complex framework like Moodle, the presence of numerous internal classes provides a large surface area for potential 'gadget' chaining, potentially leading to privilege escalation or further remote code execution scenarios depending on the interaction between instantiated objects and the wider system state."
}
CVE-2026-102580: Moodle Report Builder Object Injection (LOW Severity, CVSS: 2.2) | Sceawere