VYPR
High severity7.2NVD Advisory· Published Feb 21, 2026· Updated Jun 17, 2026

CVE-2026-26046

CVE-2026-26046

Description

A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • osv-coords
    Range: < 4.5.9
  • Moodle/Moodle2 versions
    cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*range: <4.5.9
    • (no CPE)

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.