
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67848 is an authentication bypass vulnerability in Moodle's Learning Tools Interoperability (LTI) Provider that allows suspended users to authenticate and gain unauthorized access to the system. The flaw was reported internally on December 19, 2025, and publicly disclosed on February 3, 2026. It affects Moodle versions prior to 4.1.22, 4.4.0–4.4.11, 4.5.0–4.5.7, 5.0.0–5.0.3, and 5.1.0 (fixed in 4.1.22, 4.4.12, 4.5.8, 5.0.4, and 5.1.1). The vulnerability carries a CVSS v3.1 base score of 8.1 (High) (Github Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-280 (Improper Handling of Insufficient Permissions or Privileges): the LTI authentication handlers in Moodle fail to check whether a user account is in a suspended state before completing authentication. When a suspended user initiates an LTI-based login flow, the handler proceeds without enforcing the suspension flag, effectively bypassing the access restriction. Exploitation requires only low-level (previously valid) credentials and is performed remotely over the network with no user interaction required. Patch commits 62f372e and c2705e2 in the moodle/moodle repository address the missing suspension-status enforcement (Github Advisory, Red Hat Bugzilla).
Successful exploitation allows a suspended (and therefore unauthorized) user to regain access to a Moodle instance, resulting in high confidentiality and high integrity impact with no availability impact. An attacker can access sensitive course content, student data, grades, and personal information, and may also be able to modify records or perform administrative actions depending on the role the suspended account previously held. The scope is limited to the affected Moodle instance, but the data exposure risk is significant in educational environments where personally identifiable information (PII) is routinely stored (Github Advisory, Feedly).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.048% (15th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Github Advisory, Feedly).
logstore_standard_log entries with action=loggedin and component=mod_lti for suspended user IDs.mdl_sessions table for user accounts with suspended=1 in mdl_user./mod/lti/ or /enrol/lti/ endpoints originating from external LTI tool providers, followed by authenticated activity from accounts that should be inactive.Moodle has released patched versions: 4.1.22, 4.4.12, 4.5.8, 5.0.4, and 5.1.1. Administrators should upgrade to the appropriate patched release immediately. As a temporary workaround prior to patching, administrators can disable LTI Provider functionality in Moodle site settings to prevent the vulnerable authentication path from being used. Additionally, conducting an audit of suspended user accounts for any recent login activity is recommended to identify potential unauthorized access (Github Advisory, Moodle Forum).
The vulnerability was noted in a CISA weekly vulnerability bulletin (week of February 2, 2026) and referenced by Red Hat's Product Security team via Bugzilla and their CVE portal. A Mastodon post from @thehackerwire briefly highlighted the disclosure. No significant independent researcher commentary or major media coverage has been identified beyond standard vulnerability aggregator coverage (CISA Bulletin, Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."