OCTOBER 4, 2026
Live Feed
Back to database
Case File

CVE-2026-102583

LOW · CVSS 2.7 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-04

CyberRota Analysis

AI-Generated

A vulnerability in Moodle's AI image generation web service allows authenticated users to bypass capability checks, enabling unauthorized access to this feature. While the severity is rated low, it poses a risk of misuse by users who should not have access to the AI functionality. Organizations using Moodle should prioritize patching this flaw to prevent unauthorized exploitation of the AI image generation capabilities.

CVE
CVE-2026-102583
Severity
LOW
CVSS
2.7
EPSS
0.24%

Original NVD Description

A flaw was found in Moodle. An incorrect capability check in the artificial intelligence (AI) editor placement's image generation web service allows an authenticated user to invoke the feature without holding the required capability. This flaw permits unauthorized users to access and utilize the AI image generation functionality.

Related CVEs

Other vulnerabilities affecting the same vendor(s)