Description
A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server.
Published: 2026-02-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Command injection leading to full server compromise via administrative TeX filter configuration
Action: Apply Patch
AI Analysis

Impact

A Moodle TeX filter administrators setting accepts input that is not fully sanitized, allowing a crafted value to inject system commands. The weakness, identified as CWE‑78, means a malicious entry could be executed as the Moodle server process, potentially running arbitrary shell commands.

Affected Systems

All Moodle installations that have the TeX filter enabled and have ImageMagick installed are at risk. The specific versions affected are not listed, so any Moodle deployment with the default TeX filtering mechanism and ImageMagick may be vulnerable.

Risk and Exploitability

The CVSS score of 7.2 classifies this vulnerability as high severity, but the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. Exploitation requires administrative privileges within the Moodle site; once achieved, the attacker can affect the entire server. The vulnerability is not yet recorded in CISA’s KEV catalog, but could become a target for attackers looking for privileged access to compromised Moodle instances.

Generated by OpenCVE AI on April 17, 2026 at 16:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Moodle to the latest version that includes the fix for the TeX filter sanitization flaw.
  • If patching is delayed, disable the TeX filter externally by removing or commenting out the corresponding entry in the Moodle configuration settings.
  • Configure ImageMagick so that it is not invoked by Moodle (for example, by setting the configuration option to use a safe image library or by restricting the execute permissions of ImageMagick binaries).

Generated by OpenCVE AI on April 17, 2026 at 16:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 26 Feb 2026 20:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*

Mon, 23 Feb 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 23 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Moodle
Moodle moodle
Vendors & Products Moodle
Moodle moodle

Sat, 21 Feb 2026 06:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server.
Title Moodle: moodle: improper input sanitization in tex filter administration setting
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2026-02-26T14:44:11.847Z

Reserved: 2026-02-10T13:30:03.985Z

Link: CVE-2026-26046

cve-icon Vulnrichment

Updated: 2026-02-23T19:31:19.520Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-21T06:17:00.203

Modified: 2026-02-26T19:46:57.600

Link: CVE-2026-26046

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-17T17:00:10Z

Weaknesses