Bug 2494836 (CVE-2026-58348) - CVE-2026-58348 moodle: Missing capability checks in report builder fragment callbacks
Summary: CVE-2026-58348 moodle: Missing capability checks in report builder fragment c...
Keywords:
Status: NEW
Alias: CVE-2026-58348
Deadline: 2026-07-01
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2507957
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-30 10:39 UTC by OSIDB Bzimport
Modified: 2026-07-28 10:56 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-06-30 10:39:19 UTC
MSA-26-0029: Missing capability checks in report builder fragment callbacks

Description:       The report builder fragment output callbacks did not verify
that the requesting user had the required capability to
access the requested report, potentially allowing users to
retrieve report data beyond their permitted access.
Issue summary:     Missing capability checks in report builder fragment
callbacks
Severity/Risk:     Minor
Versions affected: 5.2, 5.1 to 5.1.4, 5.0 to 5.0.7, 4.5 to 4.5.11 and earlier
unsupported versions
Versions fixed:    5.2.1, 5.1.5, 5.0.8 and 4.5.12
Reported by:       Paul Holden
Issue no.:         MDL-84535


Note You need to log in before you can comment on or make changes to this bug.