CVE-2026-26045: Moodle: moodle: improper validation in file restore functionality leading to remote code execution
A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead to unintended execution of server-side code. Since restore capabilities are typically available to privileged users, exploitation requires authenticated access. Successful exploitation could result in full compromise of the Moodle server.
Other sources
A Remote Code Execution vulnerability exists in Moodle’s file restore functionality due to insufficient validation of backup file contents during the restore process. An authenticated user with restore permissions can upload a specially crafted Moodle backup archive that may trigger execution of arbitrary PHP code when processed by the server. Successful exploitation could result in complete compromise of the Moodle instance, including unauthorized access to data, system modification, or service disruption.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26045?
CVE-2026-26045 has been classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2026-26045?
To fix CVE-2026-26045, ensure that you apply the latest security patches provided by Moodle that address the improper validation in the backup restore functionality.
What systems are affected by CVE-2026-26045?
CVE-2026-26045 affects all versions of Moodle with the vulnerable backup restore functionality.
What kind of attack can be executed with CVE-2026-26045?
An attacker can exploit CVE-2026-26045 by restoring a malicious backup file that allows for remote code execution.
What should I do if I am using an affected version of Moodle regarding CVE-2026-26045?
If you are using an affected version of Moodle, immediately update to the patched version and review your backup files for any suspicious activity.