Sceawere

Vulnerability Detail

CVE-2026-102582UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Moodle Manual Enrolment Access Bypass

Vulnerability Metadata

Severity
Low
Score / CVSS
2.2
Creation Date
3h ago
Vendor
—
Product
N/A
Attack Type
Direct Request ('Forced Browsing')
Vector String
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

A flaw was found in Moodle. The manual enrolment management page did not properly check whether the manual enrolment plugin was disabled, allowing users with enrolment permissions to access the page directly by navigating to its URL. Consequently, an authorized user could manage manual enrolments even after an administrator disabled the feature in the user interface.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "2.2",
  "pubDate": "2026-09-30T09:17:15.350Z",
  "pubdate": "2026-09-30T09:17:15.350Z",
  "executiveSummary": "A broken access control vulnerability exists in Moodle where the manual enrolment management interface fails to validate the current status of the manual enrolment plugin. This flaw allows users possessing standard enrolment permissions to interact with and manage manual enrolments even when the plugin has been explicitly disabled by an administrator via the administrative interface.\nThe vulnerability resides within the authorization logic of the manual enrolment management page. By directly navigating to the URL of the management interface, an authenticated user with sufficient privileges can bypass the administrative configuration toggle, effectively rendering the site-wide disabling of the manual enrolment plugin ineffective.\nThe impact includes unauthorized modification of course enrolment states, potentially leading to unauthorized access to restricted course content or privilege escalation within the context of specific courses. This issue poses a significant risk to course administration integrity and policy enforcement, as administrative intent to disable specific enrolment vectors is ignored by the application's access control layer.\nExploitation requires authenticated access to the Moodle instance and specific user permissions related to enrolment management. No advanced technical skills are required, as the attack is performed via direct URL manipulation.",
  "technicalDetails": "The root cause of this vulnerability is a failure in the Moodle access control implementation within the manual enrolment management component. Specifically, the application logic responsible for rendering the manual enrolment management page neglects to perform a cross-check against the configuration state of the manual enrolment plugin. While the administration interface provides a mechanism to toggle the plugin on or off, the endpoint responsible for managing enrolments does not verify this state during the authorization phase.\nThe vulnerability manifests as a form of broken access control, specifically a failure to enforce procedural access restrictions. When an administrator disables the manual enrolment plugin, the intended behavior is for the entire management subsystem to become inaccessible or non-functional. However, the management page relies solely on user-level capability checks rather than plugin-level availability status.\nThe exploitation process follows a predictable sequence: An attacker, authenticated as a user with existing enrolment management capabilities, identifies the URL path associated with the manual enrolment management page. Regardless of the current site-wide setting for the manual enrolment plugin, the attacker navigates directly to this path. Because the underlying controller fails to implement a check to ensure the plugin is active, the system renders the interface and processes any subsequent input or management actions submitted by the attacker. This bypasses the administrative configuration entirely.\nThe technical failure is situated within the component responsible for routing and authorization for enrolment management. By failing to integrate a conditional check against the active status of the enrol_manual plugin before processing the request, the application ensures that the UI remains interactive for users who technically possess the requisite capabilities, irrespective of the system's global state.\nPost-exploitation, the attacker maintains the ability to add, remove, or modify manual enrolments for users within courses. This allows for persistent unauthorized access to academic or organizational resources, effectively nullifying the administrator's ability to restrict or decommission the manual enrolment method as a security or policy control. The vulnerability remains present in versions where this plugin-status validation logic is absent from the manual enrolment controller."
}
CVE-2026-102582: Moodle Manual Enrolment Access Bypass (LOW Severity, CVSS: 2.2) | Sceawere