A flaw was found in Moodle. An authorization logic flaw, specifically due to incomplete role checks during the badge awarding process, allowed badges to be granted without proper verification. This could enable unauthorized users to obtain badges they are not entitled to, potentially leading to privilege escalation or unauthorized access to certain features.
References
| Link | Resource |
|---|---|
| https://access.redhat.com/security/cve/CVE-2025-67856 | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2423864 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
26 Feb 2026, 22:20
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-863 | |
| Summary |
|
11 Feb 2026, 18:58
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | NVD-CWE-noinfo | |
| First Time |
Moodle moodle
Moodle |
|
| References | () https://access.redhat.com/security/cve/CVE-2025-67856 - Third Party Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2423864 - Third Party Advisory | |
| CPE | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* cpe:2.3:a:moodle:moodle:5.1.0:*:*:*:*:*:*:* |
03 Feb 2026, 11:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-03 11:15
Updated : 2026-02-26 22:20
NVD link : CVE-2025-67856
Mitre link : CVE-2025-67856
CVE.ORG link : CVE-2025-67856
JSON object : View
Products Affected
moodle
- moodle
CWE
