CVE-2026-102580
MediumPublished
Moodle: arbitrary class instantiation via report builder audience classname
- Published
- Sep 30, 2026
- Updated
- Sep 30, 2026
- Assigning CNA
- fedora
- Evidence observed
- Sep 30, 2026
Primary CVSS
4.3/ 10Medium
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NSummary
A flaw was found in Moodle. An authenticated attacker can supply an improperly validated audience class name to the Report Builder component, allowing arbitrary class instantiation. This vulnerability enables the unauthorized creation of internal program objects, which may result in unexpected application behavior.
Sources
A community-curated, verified collection of Proof-of-Concept exploits for CVEs disclosed in 2026.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.