OCTOBER 4, 2026
Live Feed
Back to database
Case File

CVE-2026-102582

LOW · CVSS 2.2 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-04

CyberRota Analysis

AI-Generated

A vulnerability in Moodle allows users with enrolment permissions to access the manual enrolment management page directly, even if the manual enrolment plugin has been disabled by an administrator. This oversight could lead to unauthorized management of enrolments, potentially compromising user access controls. Institutions using Moodle should prioritize addressing this issue to ensure proper enforcement of enrolment settings and maintain security integrity.

CVE
CVE-2026-102582
Severity
LOW
CVSS
2.2
EPSS
0.20%

Original NVD Description

A flaw was found in Moodle. The manual enrolment management page did not properly check whether the manual enrolment plugin was disabled, allowing users with enrolment permissions to access the page directly by navigating to its URL. Consequently, an authorized user could manage manual enrolments even after an administrator disabled the feature in the user interface.

Related CVEs

Other vulnerabilities affecting the same vendor(s)