Vulnerability  ·  2026-10-01

Moodle AI editor image-generation capability check bypass

VulnerabilityLow impactGlobalCVE-2026-102583
NVD published (CVSS 2.7) an incorrect-capability-check flaw allowing unauthorized use of the AI image generation feature. Low-impact authorization gap in an education platform's AI tooling.
Bypasses AI feature entitlement/quotas and any abuse controls tied to the missing capability in LMS AI deployments.
An authenticated user calls the AI editor's image-generation web service directly, bypassing the capability check that should restrict who may use the AI feature, consuming paid/limited AI quota.
Moodle affected AI editor placement (image generation web service; fixed per MDL-88587)
Apply the Moodle fix per MDL-88587 (capability check in AI editor placement image generation).
NVDMoodle commit search MDL-88587
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →