CVE-2026-102580lowCWE-470

CVE-2026-102580: low-severity vulnerability in moodle

Moodle: arbitrary class instantiation via report builder audience classname

Published

8Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 2.2epss 0.2%
exploitation probability
0.2%top 87% of all CVEs
observed exploitation
nono source reports it
A flaw was found in Moodle. An authenticated attacker can supply an improperly validated audience class name to the Report Builder component, allowing arbitrary class instantiation. This vulnerability enables the unauthorized creation of internal program objects, which may result in unexpected application behavior.
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
Affected products
moodle