Sceawere
Vulnerability Detail
CVE-2026-102584UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Moodle Unauthorized Grade Penalty Recalculation
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 3h ago
- Vendor
- —
- Product
- N/A
- Attack Type
- Direct Request ('Forced Browsing')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw was found in Moodle. Due to a missing capability check, a low-privileged authenticated user can trigger the recalculation of grade penalties without holding the required permissions. This issue allows unauthorized users to modify grade penalty records, potentially altering student assessment scores.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-09-30T09:17:15.630Z",
"pubdate": "2026-09-30T09:17:15.630Z",
"executiveSummary": "This vulnerability in Moodle involves a critical authorization bypass flaw related to grade management. Specifically, the application fails to perform necessary capability checks before processing grade penalty recalculations. This oversight allows a low-privileged authenticated user to trigger backend logic that modifies grade penalty records, potentially resulting in the unauthorized alteration of student assessment outcomes. The flaw represents an Improper Access Control issue, as the system does not enforce privilege boundaries during sensitive administrative operations. The vulnerability is exploitable by any authenticated user within the Moodle environment, posing significant risks to academic integrity and data reliability. Because the system assumes the caller possesses sufficient privileges to initiate recalculations, it lacks the defensive layers required to prevent manipulation of grades. The potential impact involves systematic grade inflation or deflation by malicious actors, undermining the trust and authenticity of the platform's grading processes. The vulnerability does not require complex prerequisites, as it relies on the internal design flaw rather than specific platform configuration errors.",
"technicalDetails": "The vulnerability resides within the Moodle gradebook subsystem, specifically in the mechanisms governing the calculation and application of grade penalties. The root cause is identified as an insufficient authorization check—specifically a missing capability validation (e.g., 'moodle/grade:manage' or similar administrative permissions) within the code responsible for processing penalty recalculations.\nIn the Moodle architecture, recalculating grade penalties is an administrative action intended to be restricted to course instructors or administrators. However, the affected endpoint or function call lacks a robust call to the `require_capability()` or `has_capability()` API. As a result, when an authenticated user sends a request to the backend service handling grade modifications, the system processes the request without verifying if the user has been granted the authority to perform such actions.\nThe attack flow proceeds as follows: First, a low-privileged authenticated user identifies the specific request or URL path responsible for triggering the penalty recalculation logic. This can be achieved through traffic analysis during normal gradebook operations. Second, the attacker crafts a malicious request targeting the recalculation controller. Because the backend code performs no validation of the requester's context, role, or capabilities, the application logic proceeds to execute database queries that update the grade penalty records associated with a given assessment or student.\nPost-exploitation, the attacker can influence the final grade values by manipulating the penalty parameters stored in the database. Because this change occurs via the native application logic, the recalculation appears as a legitimate system operation, making it difficult for administrators to distinguish between authorized grade adjustments and malicious tampering without comprehensive audit logs. This unauthorized modification of grade records effectively bypasses the integrity controls enforced by the Moodle core, allowing an attacker to manipulate assessment outcomes to their advantage. The vulnerability persists across configurations where grade penalties are enabled, as the core issue is an architectural lack of granular permission enforcement at the API or module level. The lack of strict input validation combined with missing authorization checks confirms this as a significant logic flaw within the Moodle grade management framework."
}