Insufficient CSRF token and capability checks were applied to an MNet admin setting.
| Severity/Risk: | Minor |
| Versions affected: | 5.1 to 5.1.3, 5.0 to 5.0.6, 4.5 to 4.5.10 and earlier unsupported versions |
| Versions fixed: | 5.1.4, 5.0.7 and 4.5.11 |
| Reported by: | Vincent Schneider |
| CVE identifier: | CVE-2026-7278 |
| Changes (main): | http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-84495 |
| Tracker issue: | MDL-84495 CSRF and missing capability check in admin/mnet/peers.php |