PT-2026-5964 · Moodle+1 · Moodle+1

Published

2026-02-03

·

Updated

2026-02-24

·

CVE-2025-67856

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Moodle (affected versions not specified)
Description A flaw exists in Moodle related to authorization logic. Incomplete role checks during the badge awarding process can allow badges to be granted without proper verification. This could enable unauthorized users to obtain badges they are not entitled to, potentially leading to privilege escalation or unauthorized access to features.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BIT-MOODLE-2025-67856
CVE-2025-67856
GHSA-HCM6-Q6PC-XFHM

Affected Products

Moodle
Red Os