CVE-2026-26046

A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*

History

26 Feb 2026, 19:46

Type Values Removed Values Added
First Time Moodle moodle
Moodle
Summary
  • (es) Se encontró una vulnerabilidad en una configuración administrativa del filtro TeX de Moodle donde una sanitización insuficiente de la entrada de configuración podría permitir la inyección de comandos. En sitios donde el filtro TeX está habilitado e ImageMagick está instalado, un valor de configuración maliciosamente elaborado introducido por un administrador podría resultar en la ejecución no intencionada de comandos del sistema. Si bien la explotación requiere privilegios administrativos, un compromiso exitoso podría afectar a todo el servidor Moodle.
References () https://access.redhat.com/security/cve/CVE-2026-26046 - () https://access.redhat.com/security/cve/CVE-2026-26046 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2440903 - () https://bugzilla.redhat.com/show_bug.cgi?id=2440903 - Third Party Advisory
CPE cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*

21 Feb 2026, 06:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-21 06:17

Updated : 2026-02-26 19:46


NVD link : CVE-2026-26046

Mitre link : CVE-2026-26046

CVE.ORG link : CVE-2026-26046


JSON object : View

Products Affected

moodle

  • moodle
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')