CVE-2026-26045
Gravedad CVSS v3.1:
ALTA
Tipo:
CWE-94
Control incorrecto de generación de código (Inyección de código)
Fecha de publicación:
21/02/2026
Última modificación:
21/02/2026
Descripción
*** Pendiente de traducción *** A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead to unintended execution of server-side code. Since restore capabilities are typically available to privileged users, exploitation requires authenticated access. Successful exploitation could result in full compromise of the Moodle server.
Impacto
Puntuación base 3.x
7.20
Gravedad 3.x
ALTA



