Security announcements

MSA-26-0020: Reflected XSS via Feedback import error message

by Michael Hawkins -

The Feedback activity module's import functionality required additional sanitizing to prevent a reflected XSS risk.

Severity/Risk: Minor
Versions affected: 5.2, 5.1 to 5.1.4, 5.0 to 5.0.7, 4.5 to 4.5.11 and earlier unsupported versions
Versions fixed: 5.2.1, 5.1.5, 5.0.8 and 4.5.12
Reported by: Paul Holden
CVE identifier: CVE-2026-58339
Changes (main): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-88543
Tracker issue: MDL-88543 Reflected XSS via Feedback import error message

MSA-26-0019: CSRF risk in user profile page reset

by Michael Hawkins -

The user profile page reset action did not include the necessary token to prevent a CSRF risk.

Severity/Risk: Minor
Versions affected: 5.2, 5.1 to 5.1.4, 5.0 to 5.0.7, 4.5 to 4.5.11 and earlier unsupported versions
Versions fixed: 5.2.1, 5.1.5, 5.0.8 and 4.5.12
Reported by: Paul Holden
CVE identifier: CVE-2026-58338
Changes (main): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-88545
Tracker issue: MDL-88545 CSRF risk in user profile page reset

MSA-26-0018: CSRF risk in user homepage preference setting

by Michael Hawkins -

The setting for users to set their own homepage preference did not include the necessary token to prevent a CSRF risk.

Severity/Risk: Minor
Versions affected: 5.2, 5.1 to 5.1.4, 5.0 to 5.0.7, 4.5 to 4.5.11 and earlier unsupported versions
Versions fixed: 5.2.1, 5.1.5, 5.0.8 and 4.5.12
Reported by: Paul Holden
CVE identifier: CVE-2026-58337
Changes (main): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-88609
Tracker issue: MDL-88609 CSRF risk in user homepage preference setting

MSA-26-0017: IDOR allows arbitrary comment deletion

by Michael Hawkins -

Additional checks were required to ensure users with the capability to delete comments can only do so in the contexts where they have the permission.

Severity/Risk: Serious
Versions affected: 5.2, 5.1 to 5.1.3, 5.0 to 5.0.6, 4.5 to 4.5.10 and earlier unsupported versions
Versions fixed: 5.2.1, 5.1.5, 5.0.8 and 4.5.12
Reported by: Paul Holden
CVE identifier: CVE-2026-58336
Changes (main): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-88619
Tracker issue: MDL-88619 IDOR allows arbitrary comment deletion

MSA-26-0016: Missing group access checks in grade web services

by Michael Hawkins -

Missing group access checks in some grade web services could allow a user to access grade and user information for students in groups they did not have permission to view.

Severity/Risk: Minor
Versions affected: 5.2, 5.1 to 5.1.4, 5.0 to 5.0.7, 4.5 to 4.5.11 and earlier unsupported versions
Versions fixed: 5.2.1, 5.1.5, 5.0.8 and 4.5.12
Reported by: Paul Holden
CVE identifier: CVE-2026-58335
Changes (main): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-88667
Tracker issue: MDL-88667 Missing group access checks in grade web services

MSA-26-0015: RCE risk via admin presets import

by Michael Hawkins -

A remote code execution risk was identified in the admin presets import feature. Note: This feature is only available to site administrators.

Severity/Risk: Serious
Versions affected: 5.2, 5.1 to 5.1.4, 5.0 to 5.0.7, 4.5 to 4.5.11 and earlier unsupported versions
Versions fixed: 5.2.1, 5.1.5, 5.0.8 and 4.5.12
Reported by: LoWeST
CVE identifier: CVE-2026-58334
Changes (main): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-88735
Tracker issue: MDL-88735 RCE risk via admin presets import

MSA-26-0014: Arbitrary file read risk in backup restore

by Michael Hawkins -

An arbitrary file read risk was identified in the backup restore functionality.

Severity/Risk: Serious
Versions affected: 5.2, 5.1 to 5.1.4, 5.0 to 5.0.7, 4.5 to 4.5.11 and earlier unsupported versions
Versions fixed: 5.2.1, 5.1.5, 5.0.8 and 4.5.12
Reported by: LoWeST
CVE identifier: CVE-2026-58333
Changes (main): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-88736
Tracker issue: MDL-88736 Arbitrary file read risk in backup restore

MSA-26-0013: Email-based MFA bypass

by Michael Hawkins -

A flaw in email-based multi-factor authentication made it possible for a user to bypass another user's MFA token check if using the email factor. Note: Valid login credentials (such as username and password) were still required to log into the account.

Severity/Risk: Serious
Versions affected: 5.2, 5.1 to 5.1.4, 5.0 to 5.0.7, 4.5 to 4.5.11 and earlier unsupported versions
Versions fixed: 5.2.1, 5.1.5, 5.0.8 and 4.5.12
Reported by: Brendan Heywood
CVE identifier: CVE-2026-58332
Changes (main): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-88767
Tracker issue: MDL-88767 Email-based MFA bypass

MSA-26-0012: Arbitrary file read risk in Database activity module

by Michael Hawkins -

An arbitrary file read risk was identified in the Database Activity module's import feature.

Severity/Risk: Serious
Versions affected: 5.2, 5.1 to 5.1.4, 5.0 to 5.0.7, 4.5 to 4.5.11 and earlier unsupported versions
Versions fixed: 5.2.1, 5.1.5, 5.0.8 and 4.5.12
Reported by: POVGen
CVE identifier: CVE-2026-58331
Changes (main): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-88595
Tracker issue: MDL-88595 Arbitrary file read risk in Database activity module

Socialwall course format plugin - known vulnerability and call for new maintainer

by Michael Hawkins -

Hi all,

We have been made aware of a serious security vulnerability in the third-party Socialwall course format plugin (format_socialwall). As the plugin is no longer actively maintained, no fix is forthcoming, and we consider it unsafe to use.

If you have the Socialwall plugin installed, we recommend disabling or uninstalling it as soon as possible. We have also removed that plugin from our plugins directory. If you do not have the Socialwall course format plugin installed, no action is required.

We would like to thank gr3mlin for responsibly disclosing this vulnerability to us via our security submission form, after they were unable to reach the plugin maintainer directly (we were able to subsequently reach the maintainer and confirm the plugin is no longer in active development).

Are you interested in taking over maintenance of Socialwall?

If your site is using this plugin and you have the capacity to take on its maintenance (including fixing the vulnerability), we'd love to hear from you - please reply to this thread or contact me directly.