CVE-2026-26045

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
21/02/2026
Last modified:
26/02/2026

Description

A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead to unintended execution of server-side code. Since restore capabilities are typically available to privileged users, exploitation requires authenticated access. Successful exploitation could result in full compromise of the Moodle server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 4.5.9 (excluding)
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 5.0.0 (including) 5.0.5 (excluding)
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 5.1.0 (including) 5.1.2 (excluding)