CVE-2026-102583: fallo de gravedad baja en moodle
Moodle: incorrect capability check in ai generate image web service
Publicada el
8Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 2.7epss 0.2%
probabilidad de explotación
0.2%top 86% de las CVE
explotación observada
noninguna fuente lo reporta
A flaw was found in Moodle. An incorrect capability check in the artificial intelligence (AI) editor placement's image generation web service allows an authenticated user to invoke the feature without holding the required capability. This flaw permits unauthorized users to access and utilize the AI image generation functionality.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Productos afectados
moodleCVEs relacionadas — moodle
En el mismo producto, de las más peligrosas a las menos.
CVE-2024-43425HIGHMoodle: remote code execution via calculated question typesEPSS 87.5%CVE-2023-30943MEDIUMMoodle: tinymce loaders susceptible to arbitrary folder creationEPSS 6.6%CVE-2026-26046HIGHMoodle: moodle: improper input sanitization in tex filter administration settingEPSS 3.0%CVE-2023-5540MEDIUMMoodle: authenticated remote code execution risk in imscpEPSS 1.9%CVE-2023-5539MEDIUMMoodle: authenticated remote code execution risk in lessonEPSS 1.9%CVE-2023-5550MEDIUMMoodle: rce due to lfi risk in some misconfigured shared hosting environmentsEPSS 1.4%