Description
A flaw was found in Moodle. When enrolling a user into a course while assigning them to a group, the application does not verify whether the selected group actually belongs to that course. An authenticated user with teacher privileges could exploit this flaw to add users to groups within courses they do not have authorization to access.
Published: 2026-09-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation in Moodle Course Groups
Action: Patch Now
AI Analysis

Impact

Moodle does not verify that an assigned group belongs to the target course when a teacher enrolls a user. This omission lets an authenticated teacher add a user to any group in any course, effectively giving the user access to courses they should not be able to view. The resulting privilege escalation can expose confidential course material to unauthorized users and violate institutional access controls.

Affected Systems

Any Moodle installation that uses the standard enrollment and group assignment functions and grants teachers the ability to assign a user to a group. No specific version is listed, so the vulnerability may be present in all releases that incorporate the code path affected by commit MDL-88538 until a patch is applied.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity. EPSS is not available, so the probability of exploitation is unknown, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is an authenticated teacher acting within the Moodle web interface; the attack requires no elevated system privileges but does require teacher-level access. Because the teacher can choose any group in any course, the potential impact spans multiple courses and users.

Generated by OpenCVE AI on September 30, 2026 at 11:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Moodle patch that includes group validation for enrollment (see the patch that addresses commit MDL-88538).
  • Restrict teacher permissions to only those courses they manage or temporarily disable group assignment capability until the patch reaches all servers.
  • Audit enrollment and group assignment logs for anomalies after the remediation to detect any accidental or malicious group changes.

Generated by OpenCVE AI on September 30, 2026 at 11:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Moodle
Moodle moodle
Vendors & Products Moodle
Moodle moodle

Wed, 30 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in Moodle. When enrolling a user into a course while assigning them to a group, the application does not verify whether the selected group actually belongs to that course. An authenticated user with teacher privileges could exploit this flaw to add users to groups within courses they do not have authorization to access.
Title Moodle: group validation missing when enrolling user to course
Weaknesses CWE-842
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2026-09-30T15:28:08.543Z

Reserved: 2026-09-29T14:03:38.494Z

Link: CVE-2026-102585

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T09:17:15.763

Modified: 2026-09-30T16:20:44.613

Link: CVE-2026-102585

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T12:00:16Z

Weaknesses
  • CWE-842

    Placement of User into Incorrect Group