CVE-2026-26047

A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimetex, insufficient execution time limits could allow specially crafted formulas to consume excessive server resources. An authenticated user could abuse this behavior to degrade performance or cause service interruption.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*

History

26 Feb 2026, 19:45

Type Values Removed Values Added
CWE CWE-770
Summary
  • (es) Se ha identificado una vulnerabilidad de denegación de servicio en el editor de fórmulas TeX de Moodle. Al renderizar contenido TeX usando mimetex, si los límites de tiempo de ejecución son insuficientes, podrían permitir que fórmulas especialmente diseñadas consuman excesivos recursos del servidor. Un usuario autenticado podría abusar de este comportamiento para degradar el rendimiento o causar interrupción del servicio.
References () https://access.redhat.com/security/cve/CVE-2026-26047 - () https://access.redhat.com/security/cve/CVE-2026-26047 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2440905 - () https://bugzilla.redhat.com/show_bug.cgi?id=2440905 - Third Party Advisory
First Time Moodle moodle
Moodle
CPE cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*

21 Feb 2026, 06:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-21 06:17

Updated : 2026-02-26 19:45


NVD link : CVE-2026-26047

Mitre link : CVE-2026-26047

CVE.ORG link : CVE-2026-26047


JSON object : View

Products Affected

moodle

  • moodle
CWE
CWE-400

Uncontrolled Resource Consumption

CWE-770

Allocation of Resources Without Limits or Throttling