CVE-2026-26046: Moodle: moodle: improper input sanitization in tex filter administration setting
A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26046?
CVE-2026-26046 has a medium severity level due to its potential for command injection via insufficient input sanitization.
How do I fix CVE-2026-26046?
To fix CVE-2026-26046, ensure that you update your Moodle installation to the latest version which addresses the input sanitization issue.
What does CVE-2026-26046 affect?
CVE-2026-26046 affects Moodle installations that have the TeX filter enabled and may specifically impact configurations using ImageMagick.
Can CVE-2026-26046 lead to a security breach?
Yes, CVE-2026-26046 can potentially lead to security breaches through command injection if exploited by attackers.
When was CVE-2026-26046 published?
CVE-2026-26046 was published to alert users regarding the discovered vulnerability in the Moodle TeX filter settings.