MEDIUM 4.3 NVD
CVE-2026-102584
A flaw was found in Moodle. Due to a missing capability check, a low-privileged authenticated user can trigger the recalculation of grade penalties without hold
A flaw was found in Moodle. Due to a missing capability check, a low-privileged authenticated user can trigger the recalculation of grade penalties without holding the required permissions. This issue allows unauthorized users to modify grade penalty records, potentially altering student assessment scores.
References
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-88585
- https://access.redhat.com/security/cve/CVE-2026-102584
- https://bugzilla.redhat.com/show_bug.cgi?id=2543637
- https://moodle.org/mod/forum/discuss.php?d=482502
This medium severity vulnerability with a CVSS score of 4.3 was published on 2026-09-30 via NVD.
vulnfeed aggregates 9449 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.