← Back

CVE-2026-26046

nvd nist
Published: Feb 21, 2026Modified: Feb 26, 2026

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: patrick@puiterwijk.org (Secondary)

Description

A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server.

Affected (3)

Products: Moodle: Moodle
1 product
Moodle
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Moodle
Before 4.5.9
From 5.0.0 to 5.0.5
From 5.1.0 to 5.1.2

References (2)

Source: patrick@puiterwijk.org
Third Party Advisory
Source: patrick@puiterwijk.org
Third Party Advisory

Timeline

No history available yet.