CVE-2026-102582 PUBLISHED

Moodle: manual enrolment page accessible when plugin disabled

Assigner: fedora
Reserved: 29.09.2026 Published: 30.09.2026 Updated: 30.09.2026

A flaw was found in Moodle. The manual enrolment management page did not properly check whether the manual enrolment plugin was disabled, allowing users with enrolment permissions to access the page directly by navigating to its URL. Consequently, an authorized user could manage manual enrolments even after an administrator disabled the feature in the user interface.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
CVSS Score: 2.2

Product Status

Package Collection https://git.moodle.org
Package Name moodle
Versions Default: unaffected
  • affected from 5.2.0 to 5.2.2 (excl.)
  • affected from 5.1.0 to 5.1.6 (excl.)
  • affected from 5.0.0 to 5.0.9 (excl.)
  • affected from 0 to 4.5.13 (excl.)

Credits

  • Upstream acknowledges Paul Holden as the original reporter.

References

Problem Types

  • Direct Request ('Forced Browsing') CWE