SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-54733

CRITICAL · CVSS 9.3 EPSS 0.92% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Microsoft Office 365 Integration plugin for Moodle prior to versions 4.5.6, 5.0.5, and 5.1.1 is vulnerable due to improper verification of JWT signatures in the Teams SSO endpoint, allowing unauthenticated attackers to forge tokens and gain unauthorized access to Moodle sessions as O365-authenticated users. This vulnerability poses a significant risk to organizations using these versions of the plugin, particularly those relying on Office 365 and Azure Active Directory for authentication. Administrators should prioritize updating to the patched versions to mitigate the risk of unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-54733
Severity
CRITICAL
CVSS
9.3
EPSS
0.92%
Microsoft Office

Original NVD Description

The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0.5, and 5.1.1, the Microsoft Office 365 Integration plugin local_o365 Teams SSO endpoint sso_login.php base64-decodes a JWT payload and authenticates users from the upn claim without verifying the JWT signature, allowing an unauthenticated attacker to forge a token and obtain a Moodle session as an O365-authenticated user. This issue is fixed in versions 4.5.6, 5.0.5, and 5.1.1.