Description
A flaw was found in Moodle. An incorrect capability check in the grade web service allows an authenticated student to access profile information of other students enrolled in the same course that they should not have permission to view. This issue leads to unauthorized information disclosure.
Published: 2026-09-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply patch
AI Analysis

Impact

A flaw was discovered in the Moodle grade web service where an incorrect capability check allows an authenticated student to view the profile information of other students in the same course. This vulnerability leads to unauthorized disclosure of personal data. Based on the description, the attack vector is an authenticated user utilizing the web service; the attacker must be logged in to the Moodle environment and enrolled in the target course.

Affected Systems

The affected product is Moodle, specifically its web-based grade web service functionality. No specific version numbers are listed in the data, so any Moodle installation that has not yet incorporated the fix through an update may be vulnerable.

Risk and Exploitability

The CVSS score is 4.3, indicating low severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting that exploitation is currently unlikely to occur on a large scale. An attacker would need to authenticate as a student with enrollment in the relevant course, then invoke the grade web service; if the correct role permissions are not enforced, the student's profile data becomes visible.

Generated by OpenCVE AI on September 30, 2026 at 11:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check the Moodle or vendor website for an available patch that addresses the capability check in the grade web service.
  • Apply any released update or patch to the Moodle installation to remediate the information disclosure flaw.
  • If no patch is available, restrict access to the grade web service so that only teachers or authorized personnel can invoke it, and consider disabling the service for student users

Generated by OpenCVE AI on September 30, 2026 at 11:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Moodle
Moodle moodle
Vendors & Products Moodle
Moodle moodle

Wed, 30 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in Moodle. An incorrect capability check in the grade web service allows an authenticated student to access profile information of other students enrolled in the same course that they should not have permission to view. This issue leads to unauthorized information disclosure.
Title Moodle: user profile information disclosure via grade web service
Weaknesses CWE-359
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2026-09-30T14:36:22.923Z

Reserved: 2026-09-29T14:03:38.493Z

Link: CVE-2026-102579

cve-icon Vulnrichment

Updated: 2026-09-30T14:36:19.483Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T09:17:14.947

Modified: 2026-09-30T16:20:44.613

Link: CVE-2026-102579

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T12:00:16Z

Weaknesses
  • CWE-359

    Exposure of Private Personal Information to an Unauthorized Actor