{"api_version":"1","generated_at":"2026-10-01T19:17:14+00:00","cve":"CVE-2026-102579","urls":{"html":"https://cve.report/CVE-2026-102579","api":"https://cve.report/api/cve/CVE-2026-102579.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-102579","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-102579"},"summary":{"title":"Moodle: user profile information disclosure via grade web service","description":"A flaw was found in Moodle. An incorrect capability check in the grade web service allows an authenticated student to access profile information of other students enrolled in the same course that they should not have permission to view. This issue leads to unauthorized information disclosure.","state":"PUBLISHED","assigner":"fedora","published_at":"2026-09-30 09:17:14","updated_at":"2026-10-01 14:21:12"},"problem_types":["CWE-359","CWE-359 Exposure of Private Personal Information to an Unauthorized Actor"],"metrics":[{"version":"3.1","source":"patrick@puiterwijk.org","type":"Secondary","score":"4.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"4.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","version":"3.1"}}],"references":[{"url":"https://moodle.org/mod/forum/discuss.php?d=482497","name":"https://moodle.org/mod/forum/discuss.php?d=482497","refsource":"patrick@puiterwijk.org","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-89381","name":"http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-89381","refsource":"patrick@puiterwijk.org","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2543633","name":"https://bugzilla.redhat.com/show_bug.cgi?id=2543633","refsource":"patrick@puiterwijk.org","tags":["Issue Tracking","Third Party Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/security/cve/CVE-2026-102579","name":"https://access.redhat.com/security/cve/CVE-2026-102579","refsource":"patrick@puiterwijk.org","tags":["Third Party Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-102579","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102579","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[{"source":"CNA","time":"2026-09-09T13:08:58.000Z","lang":"en","value":"Reported to Red Hat."},{"source":"CNA","time":"2026-09-29T20:17:12.000Z","lang":"en","value":"Made public."}],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Upstream acknowledges Itamarperetz2c7cc5 as the original reporter.","lang":"en"}],"nvd_cpes":[{"cve_year":"2026","cve_id":"102579","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"moodle","cpe5":"moodle","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-102579","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-09-30T14:36:10.291452Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-30T14:36:22.923Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"collectionURL":"https://git.moodle.org","defaultStatus":"unaffected","packageName":"moodle","versions":[{"lessThan":"5.2.2","status":"affected","version":"5.2.0","versionType":"semver"},{"lessThan":"5.1.6","status":"affected","version":"5.1.0","versionType":"semver"},{"lessThan":"5.0.9","status":"affected","version":"5.0.0","versionType":"semver"},{"lessThan":"4.5.13","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","value":"Upstream acknowledges Itamarperetz2c7cc5 as the original reporter."}],"datePublic":"2026-09-29T20:17:12.000Z","descriptions":[{"lang":"en","value":"A flaw was found in Moodle. An incorrect capability check in the grade web service allows an authenticated student to access profile information of other students enrolled in the same course that they should not have permission to view. This issue leads to unauthorized information disclosure."}],"metrics":[{"other":{"content":{"namespace":"https://access.redhat.com/security/updates/classification/","value":"Moderate"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"format":"CVSS"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-359","description":"Exposure of Private Personal Information to an Unauthorized Actor","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-30T08:36:04.097Z","orgId":"92fb86c3-55a5-4fb5-9c3f-4757b9e96dc5","shortName":"fedora"},"references":[{"url":"http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-89381"},{"tags":["vdb-entry","x_refsource_REDHAT"],"url":"https://access.redhat.com/security/cve/CVE-2026-102579"},{"name":"RHBZ#2543633","tags":["issue-tracking","x_refsource_REDHAT"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2543633"},{"url":"https://moodle.org/mod/forum/discuss.php?d=482497"}],"timeline":[{"lang":"en","time":"2026-09-09T13:08:58.000Z","value":"Reported to Red Hat."},{"lang":"en","time":"2026-09-29T20:17:12.000Z","value":"Made public."}],"title":"Moodle: user profile information disclosure via grade web service","x_generator":{"engine":"cvelib 1.8.0"},"x_redhatCweChain":"CWE-359: Exposure of Private Personal Information to an Unauthorized Actor"}},"cveMetadata":{"assignerOrgId":"92fb86c3-55a5-4fb5-9c3f-4757b9e96dc5","assignerShortName":"fedora","cveId":"CVE-2026-102579","datePublished":"2026-09-30T08:36:04.097Z","dateReserved":"2026-09-29T14:03:38.493Z","dateUpdated":"2026-09-30T14:36:22.923Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-30 09:17:14","lastModifiedDate":"2026-10-01 14:21:12","problem_types":["CWE-359","CWE-359 Exposure of Private Personal Information to an Unauthorized Actor"],"metrics":{"cvssMetricV31":[{"source":"patrick@puiterwijk.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-30T14:36:10.291452Z","id":"CVE-2026-102579","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*","versionEndExcluding":"4.5.13","matchCriteriaId":"99FF93A9-D754-4DE4-8D1B-B4C324CDA91A"},{"vulnerable":true,"criteria":"cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0.0","versionEndExcluding":"5.0.9","matchCriteriaId":"11BA4A97-DFEA-4813-B107-4BA4C0BD78DB"},{"vulnerable":true,"criteria":"cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*","versionStartIncluding":"5.1.0","versionEndExcluding":"5.1.6","matchCriteriaId":"37F95B02-166C-45BA-B537-21CB5084001F"},{"vulnerable":true,"criteria":"cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2.0","versionEndExcluding":"5.2.2","matchCriteriaId":"EFDDCBAE-2DFF-45D6-A90A-2A9AC1743722"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"102579","Ordinal":"1","Title":"Moodle: user profile information disclosure via grade web servic","CVE":"CVE-2026-102579","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"102579","Ordinal":"1","NoteData":"A flaw was found in Moodle. An incorrect capability check in the grade web service allows an authenticated student to access profile information of other students enrolled in the same course that they should not have permission to view. This issue leads to unauthorized information disclosure.","Type":"Description","Title":"Moodle: user profile information disclosure via grade web servic"}]}}}