CVE-2026-26045
EUVD-2026-739021.02.2026, 06:16
A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead to unintended execution of server-side code. Since restore capabilities are typically available to privileged users, exploitation requires authenticated access. Successful exploitation could result in full compromise of the Moodle server.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| moodle | moodle | 𝑥 < 4.5.9 |
| moodle | moodle | 5.0.0 ≤ 𝑥 < 5.0.5 |
| moodle | moodle | 5.1.0 ≤ 𝑥 < 5.1.2 |
𝑥
= Vulnerable software versions