High severityNVD Advisory· Published Feb 21, 2026· Updated Feb 26, 2026
Moodle: moodle: improper validation in file restore functionality leading to remote code execution
CVE-2026-26045
Description
A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead to unintended execution of server-side code. Since restore capabilities are typically available to privileged users, exploitation requires authenticated access. Successful exploitation could result in full compromise of the Moodle server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
moodle/moodlePackagist | >= 5.1.0-beta, < 5.1.2 | 5.1.2 |
moodle/moodlePackagist | >= 5.0.0-beta, < 5.0.5 | 5.0.5 |
moodle/moodlePackagist | < 4.5.9 | 4.5.9 |
Affected products
2- osv-coords2 versions
< 4.5.9+ 1 more
- (no CPE)range: < 4.5.9
- (no CPE)range: >= 5.1.0-beta, < 5.1.2
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-ggxq-2mg9-8966ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-26045ghsaADVISORY
- access.redhat.com/security/cve/CVE-2026-26045ghsavdb-entryx_refsource_REDHATWEB
- bugzilla.redhat.com/show_bug.cgighsaissue-trackingx_refsource_REDHATWEB
- github.com/moodle/moodle/commit/566054ba11f609a6d48d09b32e85d435d49927daghsaWEB
- moodle.org/mod/forum/discuss.phpghsaWEB
News mentions
0No linked articles in our index yet.