Moodle LMS 3.9.2: authenticated file-upload validation bypass (CWE-434) leading to RCE under misconfiguration
Researcher reports an authenticated Moodle 3.9.2 file-upload bypass that can yield RCE if misconfigured.
A researcher disclosed an authenticated unrestricted file-upload flaw (CWE-434 and CWE-20) in Moodle LMS 3.9.2 that can lead to remote code execution when the site is misconfigured. Other versions have not been verified. Moodle, a CVE Numbering Authority, has not assigned a CVE after coordinated disclosure, and a MITRE request tracked as CAN-2026-2032565 has been pending for about three months.
- Confirmed only on Moodle LMS 3.9.2; other versions are unverified.
- Authenticated upload validation bypass can lead to RCE under misconfiguration.
- No CVE yet; MITRE request CAN-2026-2032565 has been pending about three months.
Posted by Muhammad Arslan Official on Sep 28 Hello, I am disclosing a vulnerability in Moodle LMS and requesting a CVE ID, as the vendor (a registered CNA) has not assigned one after coordinated disclosure, and a MITRE CNA-LR request (CAN-2026-2032565) has been under review for ~3 months without response. Product: Moodle LMS Confirmed version: 3.9.2 (other versions not yet verified) Class: CWE-434 / CWE-20 - Unrestricted file upload / improper input validation Privilege required:...
This source does not provide full text. Read it at seclists.org.