Description
A flaw was found in Moodle. An incorrect capability check in the artificial intelligence (AI) editor placement's image generation web service allows an authenticated user to invoke the feature without holding the required capability. This flaw permits unauthorized users to access and utilize the AI image generation functionality.
Published: 2026-09-30
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized AI image generation
Action: Assess Impact
AI Analysis

Impact

The vulnerability in Moodle’s AI image generation web service arises from an incorrect capability check. An authenticated user who does not possess the necessary capability can trigger image generation. This allows unauthorized AI‑generated content to be created without prior permission. The weakness is identified as improper authorization (CWE‑425).

Affected Systems

All Moodle deployments that include the AI image generation feature are potentially affected. No specific version restrictions are disclosed, implying that any current or future release that implements the web service may be vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 2.7 classifies the flaw as low severity. EPSS is not available, so the potential for exploitation is unclear but likely modest. The attack requires an authenticated account; an attacker must first obtain valid credentials. Based on the description, there is no explicit indication that the flaw provides arbitrary code execution or direct data compromise. The vulnerability enables privileged AI image generation beyond what the user is authorized to perform, but does not appear to expose sensitive data or allow broader system compromise. Since the flaw is not listed in CISA’s KEV catalog, no active exploitation has been reported.

Generated by OpenCVE AI on September 30, 2026 at 12:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Moodle release that includes the fix for the incorrect capability check.
  • Restrict the AI image generation capability to only the roles explicitly authorized for that action.
  • If a patch is not yet available, disable the AI image generation web service or restrict its use to a trusted set of users.

Generated by OpenCVE AI on September 30, 2026 at 12:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Moodle
Moodle moodle
Vendors & Products Moodle
Moodle moodle

Wed, 30 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in Moodle. An incorrect capability check in the artificial intelligence (AI) editor placement's image generation web service allows an authenticated user to invoke the feature without holding the required capability. This flaw permits unauthorized users to access and utilize the AI image generation functionality.
Title Moodle: incorrect capability check in ai generate image web service
Weaknesses CWE-425
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2026-09-30T08:36:12.710Z

Reserved: 2026-09-29T14:03:38.494Z

Link: CVE-2026-102583

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T09:17:15.493

Modified: 2026-09-30T09:17:15.493

Link: CVE-2026-102583

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T12:30:17Z

Weaknesses
  • CWE-425

    Direct Request ('Forced Browsing')