Bug 2494831 (CVE-2026-58343) - CVE-2026-58343 moodle: Missing capability checks in AI placement web services
Summary: CVE-2026-58343 moodle: Missing capability checks in AI placement web services
Keywords:
Status: NEW
Alias: CVE-2026-58343
Deadline: 2026-07-01
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2507965
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-30 10:31 UTC by OSIDB Bzimport
Modified: 2026-07-28 11:04 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-06-30 10:31:52 UTC
MSA-26-0024: Missing capability checks in AI placement web services

Description:       Capability checks were missing from course assistance AI
placement web services, which could allow users to make
requests to those AI course assistance web services without
having the relevant capabilities (if those features are
enabled).
Issue summary:     Missing capability checks in AI placement web services
Severity/Risk:     Minor
Versions affected: 5.2, 5.1 to 5.1.4, 5.0 to 5.0.7, 4.5 to 4.5.11 and earlier
unsupported versions
Versions fixed:    5.2.1, 5.1.5, 5.0.8 and 4.5.12
Reported by:       Paul Holden
Issue no.:         MDL-88533


Note You need to log in before you can comment on or make changes to this bug.