OCTOBER 4, 2026
Live Feed
Back to database
Case File

CVE-2026-102586

MEDIUM · CVSS 4.3 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-04

CyberRota Analysis

AI-Generated

A vulnerability in Moodle allows for insufficient sanitization of username input on the password reset page, enabling remote attackers to perform cross-site scripting (XSS) attacks. By tricking an unauthenticated user into clicking a malicious password reset link, attackers can execute arbitrary scripts in the user's browser, potentially leading to data theft or session hijacking. Organizations using Moodle should prioritize addressing this issue to protect their users from potential exploitation.

CVE
CVE-2026-102586
Severity
MEDIUM
CVSS
4.3
EPSS
0.28%

Original NVD Description

A flaw was found in Moodle. Insufficient sanitization of username input on the password reset page allows a remote attacker to conduct a cross-site scripting (XSS) attack. By convincing an unauthenticated user to access a specially crafted password reset link, an attacker could execute arbitrary script in the victim's browser.

Related CVEs

Other vulnerabilities affecting the same vendor(s)