CVE-2026-102584
MEDIUM
NVD
CVSS Score
4.3
Severity
MEDIUM
Published
Sep 30, 2026
Vendor
unknown
Description
A flaw was found in Moodle. Due to a missing capability check, a low-privileged authenticated user can trigger the recalculation of grade penalties without holding the required permissions. This issue allows unauthorized users to modify grade penalty records, potentially altering student assessment scores.