CVE-2026-102583
Moodle: incorrect capability check in ai generate image web service
CVSS Score
2.7
EPSS Score
0.0%
EPSS Percentile
0th
A flaw was found in Moodle. An incorrect capability check in the artificial intelligence (AI) editor placement's image generation web service allows an authenticated user to invoke the feature without holding the required capability. This flaw permits unauthorized users to access and utilize the AI image generation functionality.
| CWE | CWE-425 |
| Published | Sep 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for
Be the first to know when new low vulnerabilities are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
References
git.moodle.org: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-88587 access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-102583 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2543640 moodle.org: https://moodle.org/mod/forum/discuss.php?d=482501
Credits
Upstream acknowledges Paul Holden as the original reporter.