Bug 2507862 (CVE-2026-18025)

Summary: CVE-2026-18025 moodle: Site Plugin Can Read Tokens From Other Stored Sites
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
Insufficient Moodle app token isolation made it possible for a Moodle site being logged into the app to access secure-storage tokens for other Moodle sites the user already had configured in their Moodle mobile app. This could result in compromise of the user’s web service token if, for example, they were tricked into logging into a malicious Moodle site in the Moodle app via a deep-link.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2507865    
Bug Blocks:    

Description OSIDB Bzimport 2026-07-28 04:41:20 UTC
Description: Moodle App lets mobile site-plugin JavaScript from one Moodle site read secure-storage tokens for other Moodle sites already configured in the app. A co-installed malicious Android app can open Moodle App to an attacker-controlled fake Moodle site; after the user accepts Moodle's site-change prompt, attacker site-plugin JS runs inside Moodle App and steals the victim site's webservice token

Versions affected: 5.2.0 and earlier unsupported versions
Versions fixed: 5.2.1