Bug 2494831 (CVE-2026-58343)
| Summary: | CVE-2026-58343 moodle: Missing capability checks in AI placement web services | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | security-response-team |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Moodle. Capability checks were missing from course assistance AI (Artificial Intelligence) placement web services. This could allow users to make requests to these web services without possessing the necessary permissions, potentially leading to unauthorized access to AI course assistance features.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2507965 | ||
| Bug Blocks: | |||
| Deadline: | 2026-07-01 | ||
|
Description
OSIDB Bzimport
2026-06-30 10:31:52 UTC
|