Description
A flaw was found in Moodle. The manual enrolment management page did not properly check whether the manual enrolment plugin was disabled, allowing users with enrolment permissions to access the page directly by navigating to its URL. Consequently, an authorized user could manage manual enrolments even after an administrator disabled the feature in the user interface.
Published: 2026-09-30
Score: 2.2 Low
EPSS: < 1% Very Low
KEV: No
Impact: Privilege escalation via exposed manual enrolment page
Action: Patch immediately
AI Analysis

Impact

A flaw in Moodle’s manual enrolment management page failed to verify whether the manual enrolment plugin was disabled, letting users with enrolment permissions bypass the administrative setting by navigating directly to the page’s URL and modify enrolments even after the feature had been turned off. This bypass enables an authorized user to perform actions outside the intended scope, constituting a privilege escalation problem aligned with CWE‑425.

Affected Systems

The vulnerability affects Moodle installations that rely on the manual enrolment plugin. No specific version of Moodle is listed in the advisory, so any deployment using the plugin and running a version that has not yet applied the corrective change is potentially impacted. Administrators should review their current Moodle version and confirm whether the patch is included.

Risk and Exploitability

The CVSS score of 2.2 indicates low severity, and the EPSS score is not available, suggesting limited public exploitation data. The vulnerability is not listed in the CISA KEV catalog. Because the attack requires an authenticated user with enrolment permissions, the exploitation vector is likely internal or requires compromised credentials. While the risk to confidentiality, integrity, or availability is modest, the ability to override administrative intent could be significant in environments with strict enrolment controls. Therefore, the recommended approach is to apply the vendor fix promptly and limit enrolment permissions to trusted administrators.

Generated by OpenCVE AI on September 30, 2026 at 11:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Moodle release or the specific patch that enforces the plugin enabled check on the manual enrolment page. This will prevent authenticated users from accessing the page when the plugin is disabled.
  • Restrict enrolment management permissions to a minimal set of trusted administrators by reviewing the role assignments for enrolment helpers and removing unnecessary permissions.
  • Verify that the manual enrolment plugin is disabled in the site administration interface and that no users retain the ability to add or manage enrolments through the URL. Re-enabling the plugin temporarily should not expose the page to unauthorized users after the patch is applied.

Generated by OpenCVE AI on September 30, 2026 at 11:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Moodle
Moodle moodle
Vendors & Products Moodle
Moodle moodle

Wed, 30 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in Moodle. The manual enrolment management page did not properly check whether the manual enrolment plugin was disabled, allowing users with enrolment permissions to access the page directly by navigating to its URL. Consequently, an authorized user could manage manual enrolments even after an administrator disabled the feature in the user interface.
Title Moodle: manual enrolment page accessible when plugin disabled
Weaknesses CWE-425
References
Metrics cvssV3_1

{'score': 2.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2026-09-30T14:34:06.857Z

Reserved: 2026-09-29T14:03:38.494Z

Link: CVE-2026-102582

cve-icon Vulnrichment

Updated: 2026-09-30T14:34:03.666Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T09:17:15.350

Modified: 2026-09-30T16:20:44.613

Link: CVE-2026-102582

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T11:30:18Z

Weaknesses
  • CWE-425

    Direct Request ('Forced Browsing')