Sceawere
Vulnerability Detail
CVE-2026-102585UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Moodle Improper Authorization Group Enrollment
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 3h ago
- Vendor
- —
- Product
- N/A
- Attack Type
- Placement of User into Incorrect Group
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw was found in Moodle. When enrolling a user into a course while assigning them to a group, the application does not verify whether the selected group actually belongs to that course. An authenticated user with teacher privileges could exploit this flaw to add users to groups within courses they do not have authorization to access.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-09-30T09:17:15.763Z",
"pubdate": "2026-09-30T09:17:15.763Z",
"executiveSummary": "This vulnerability involves an improper authorization flaw within Moodle concerning the user enrollment process. Specifically, the application fails to perform adequate validation to ensure that a selected group is logically associated with the target course during the user enrollment workflow.\nAn authenticated attacker possessing teacher-level privileges can exploit this lack of server-side validation to manipulate group memberships in courses where they lack explicit authorization. By submitting crafted requests that reference cross-course group identifiers, an attacker can bypass access control boundaries.\nThe risk implication is a compromise of course-level data integrity and unauthorized information disclosure, as enrolling users into restricted groups may grant them unintended access to course-specific resources, activities, or discussions. Successful exploitation requires an authenticated user with existing teacher privileges to initiate the enrollment action. No specialized external network access is required, as the exploit is performed through standard administrative interfaces.",
"technicalDetails": "The root cause of this vulnerability lies in the lack of referential integrity and access control validation within the Moodle enrollment service layer. When an administrator or teacher initiates a user enrollment action and specifies a group ID, the system performs the database operation without verifying that the provided group identifier is constrained to the context of the course identified in the request.\nDuring the standard enrollment workflow, the application collects the user ID, the target course ID, and the optional group ID from the request parameters. A secure implementation should perform a lookup to confirm that the group is a child of the course category or strictly belongs to the course ID provided. The current implementation bypasses this validation, treating the group assignment as an independent operation.\nThe attack flow proceeds as follows: First, the attacker identifies a target course for which they do not have administrative or teaching privileges. Second, the attacker discovers a valid group ID associated with that restricted course—this information is often easily obtained through internal API calls, URL enumeration, or previous authorized access within the platform. Third, the attacker initiates an enrollment request for a user within a course they do control, or leverages an existing enrollment workflow, but injects the target group ID into the request payload.\nBecause the server-side logic fails to validate the association between the course context and the group entity, the database query executes the linkage between the user and the unauthorized group. This effectively bypasses the scoping logic intended to limit group management to authorized course personnel.\nThe impact of this exploit is significant in multi-tenant or large institutional Moodle environments where course silos are critical for data security. Post-exploitation, the unauthorized user gains membership in a private group, which may allow them to access private forums, submit assignments in restricted buckets, or view collaborative materials that were intended to be private to the legitimate members of that course. This constitutes a privilege escalation and a breach of data privacy boundaries, as the attacker has effectively manipulated the enrollment state to circumvent standard access control policies."
}