A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server.
References
| Link | Resource |
|---|---|
| https://access.redhat.com/security/cve/CVE-2026-26046 | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2440903 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
26 Feb 2026, 19:46
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Moodle moodle
Moodle |
|
| Summary |
|
|
| References | () https://access.redhat.com/security/cve/CVE-2026-26046 - Third Party Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2440903 - Third Party Advisory | |
| CPE | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* |
21 Feb 2026, 06:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-21 06:17
Updated : 2026-02-26 19:46
NVD link : CVE-2026-26046
Mitre link : CVE-2026-26046
CVE.ORG link : CVE-2026-26046
JSON object : View
Products Affected
moodle
- moodle
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
