Bug 2494833 (CVE-2026-58345)

Summary: CVE-2026-58345 moodle: Missing capability check in Assignment marker allocation
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Moodle. Insufficient capability checks in the Assignment module allowed users without the necessary permissions to allocate markers to submissions. This vulnerability could lead to unauthorized modification of assignment data, effectively granting a limited form of privilege escalation to unauthorized users.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2507963    
Bug Blocks:    
Deadline: 2026-07-01   

Description OSIDB Bzimport 2026-06-30 10:34:51 UTC
MSA-26-0026: Missing capability check in Assignment marker allocation

Description:       Insufficient capability checks in the Assignment module's
marker allocation functionality allowed users without the
required capability to allocate markers to submissions.
Issue summary:     Missing capability check in Assignment marker allocation
Severity/Risk:     Serious
Versions affected: 5.2, 5.1 to 5.1.4, 5.0 to 5.0.7, 4.5 to 4.5.11 and earlier
unsupported versions
Versions fixed:    5.2.1, 5.1.5, 5.0.8 and 4.5.12
Reported by:       Paul Holden
Issue no.:         MDL-88529