Sceawere
Vulnerability Detail
CVE-2026-102583UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Moodle Unauthorized AI Image Access
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 2.7
- Creation Date
- 3h ago
- Vendor
- —
- Product
- N/A
- Attack Type
- Direct Request ('Forced Browsing')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw was found in Moodle. An incorrect capability check in the artificial intelligence (AI) editor placement's image generation web service allows an authenticated user to invoke the feature without holding the required capability. This flaw permits unauthorized users to access and utilize the AI image generation functionality.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "2.7",
"pubDate": "2026-09-30T09:17:15.493Z",
"pubdate": "2026-09-30T09:17:15.493Z",
"executiveSummary": "A broken access control vulnerability exists in the Moodle AI editor placement component, specifically within the image generation web service.\nThe vulnerability allows authenticated users to bypass mandatory capability checks, enabling unauthorized access to AI image generation features typically reserved for specific user roles.\nThe flaw stems from an incorrect implementation of authorization logic, failing to validate user permissions before executing the service request.\nSuccessful exploitation allows non-privileged users to invoke resource-intensive AI image generation services, potentially leading to unauthorized resource consumption, increased operational costs, and misuse of AI services integrated into the Moodle platform.\nThe vulnerability requires an authenticated session to execute the attack, as the flaw is contained within a server-side web service invoked post-authentication.\nExposure of this functionality poses a risk to service availability and organizational policy compliance regarding AI feature usage within the Moodle environment.",
"technicalDetails": "The root cause of this vulnerability is an improper capability verification mechanism within the web service responsible for the AI editor placement's image generation functionality in Moodle.\nIn the Moodle architecture, web services are designed to enforce granular capability checks, ensuring that only users granted specific permissions (e.g., 'moodle/ai:generate_image') can interact with the underlying API endpoints.\nThe vulnerability arises because the image generation service handler fails to call the 'require_capability()' or equivalent permission verification function prior to initiating the external AI service request.\nAttack flow: An authenticated user can intercept or craft an HTTP request targeted at the image generation web service endpoint. Because the server-side code does not validate the user's role-based access control (RBAC) definitions against the requested service, the application processes the request despite the user lacking the requisite capability.\nThe vulnerable component is the server-side code controlling the AI editor's image generation service. By failing to perform a context-aware authorization check during the request lifecycle, the system inherently trusts the incoming request without confirming the caller's authorization state.\nExploitation involves an authenticated user sending a specially crafted request to the AI image generation service endpoint. The request bypasses the expected access control gatekeeper, causing the server to interface with the AI generation backend on behalf of the unauthorized user.\nThe impact includes the unauthorized utilization of external AI API credits or local compute resources. Since the system treats these requests as legitimate operations due to the missing check, logs may not distinguish between authorized and unauthorized access, potentially complicating audit and incident response efforts.\nThe vulnerability is limited to authenticated sessions, meaning an attacker must possess a valid Moodle account to interact with the vulnerable service endpoint. However, since the service does not verify if the account possesses specific privileges, the effective privilege escalation allows any logged-in user to access restricted AI tools.\nThis represents a failure in the application's security model, specifically regarding the secure design of web-exposed services and the enforcement of the principle of least privilege."
}