216.73.216.36

CVE-2026-26046

· Published 21/02/2026 06:17 · Modified 21/02/2026 06:17

Labels: CVE-2026-26046 2026-02-21CVE-2026-26046CWE-78[email protected]

Essential information

Published
21/02/2026 06:17
Modified
21/02/2026 06:17
Author
Creator
CVSS
7.2 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
moodle / moodle cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
imagemagick / imagemagick cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*

References