{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-102579","assignerOrgId":"92fb86c3-55a5-4fb5-9c3f-4757b9e96dc5","state":"PUBLISHED","assignerShortName":"fedora","dateReserved":"2026-09-29T14:03:38.493Z","datePublished":"2026-09-30T08:36:04.097Z","dateUpdated":"2026-09-30T14:36:22.923Z"},"containers":{"cna":{"title":"Moodle: user profile information disclosure via grade web service","metrics":[{"other":{"content":{"value":"Moderate","namespace":"https://access.redhat.com/security/updates/classification/"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"format":"CVSS"}],"descriptions":[{"lang":"en","value":"A flaw was found in Moodle. An incorrect capability check in the grade web service allows an authenticated student to access profile information of other students enrolled in the same course that they should not have permission to view. This issue leads to unauthorized information disclosure."}],"affected":[{"versions":[{"status":"affected","version":"5.2.0","lessThan":"5.2.2","versionType":"semver"},{"status":"affected","version":"5.1.0","lessThan":"5.1.6","versionType":"semver"},{"status":"affected","version":"5.0.0","lessThan":"5.0.9","versionType":"semver"},{"status":"affected","version":"0","lessThan":"4.5.13","versionType":"semver"}],"packageName":"moodle","collectionURL":"https://git.moodle.org","defaultStatus":"unaffected"}],"references":[{"url":"http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-89381"},{"url":"https://access.redhat.com/security/cve/CVE-2026-102579","tags":["vdb-entry","x_refsource_REDHAT"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2543633","name":"RHBZ#2543633","tags":["issue-tracking","x_refsource_REDHAT"]},{"url":"https://moodle.org/mod/forum/discuss.php?d=482497"}],"datePublic":"2026-09-29T20:17:12.000Z","problemTypes":[{"descriptions":[{"cweId":"CWE-359","description":"Exposure of Private Personal Information to an Unauthorized Actor","lang":"en","type":"CWE"}]}],"x_redhatCweChain":"CWE-359: Exposure of Private Personal Information to an Unauthorized Actor","timeline":[{"lang":"en","time":"2026-09-09T13:08:58.000Z","value":"Reported to Red Hat."},{"lang":"en","time":"2026-09-29T20:17:12.000Z","value":"Made public."}],"credits":[{"lang":"en","value":"Upstream acknowledges Itamarperetz2c7cc5 as the original reporter."}],"providerMetadata":{"orgId":"92fb86c3-55a5-4fb5-9c3f-4757b9e96dc5","shortName":"fedora","dateUpdated":"2026-09-30T08:36:04.097Z"},"x_generator":{"engine":"cvelib 1.8.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-30T14:36:10.291452Z","id":"CVE-2026-102579","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-30T14:36:22.923Z"}}]}}