Vulnerability Description
A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead to unintended execution of server-side code. Since restore capabilities are typically available to privileged users, exploitation requires authenticated access. Successful exploitation could result in full compromise of the Moodle server.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Moodle | Moodle | < 4.5.9 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/security/cve/CVE-2026-26045Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2440901Third Party Advisory
FAQ
What is CVE-2026-26045?
CVE-2026-26045 is a vulnerability with a CVSS score of 7.2 (HIGH). A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead...
How severe is CVE-2026-26045?
CVE-2026-26045 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-26045?
Check the references section above for vendor advisories and patch information. Affected products include: Moodle Moodle.