
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26045 is a code injection vulnerability in Moodle's backup restore functionality, classified as "Improper Validation in File Restore Functionality Leading to Remote Code Execution." A flaw in the processing of backup files allows specially crafted archives to trigger unintended server-side PHP code execution when restored by an authenticated privileged user. Affected versions include Moodle prior to 4.5.9, 5.0.0–5.0.x prior to 5.0.5, and 5.1.0–5.1.x prior to 5.1.2. The vulnerability was published on February 19, 2026, with a CVSS v3.1 base score of 7.2 (High) (Red Hat Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-94 (Improper Control of Generation of Code / Code Injection). During the backup restore process, Moodle fails to sufficiently validate the contents of uploaded backup archive files, allowing embedded malicious PHP code to be processed and executed by the server. Exploitation requires the attacker to be authenticated with restore permissions (a privileged role), and involves uploading a specially crafted Moodle backup archive (.mbz file) that contains malicious payloads. No public proof-of-concept code has been identified at this time (Red Hat Bugzilla, Red Hat Advisory).
Successful exploitation results in full compromise of the Moodle server, including arbitrary PHP code execution with server-level privileges. This can lead to unauthorized access to sensitive data (confidentiality impact: High), unauthorized modification of system files and course content (integrity impact: High), and potential service disruption (availability impact: High). Lateral movement within the hosting environment is possible if the compromised server has network access to internal resources (Red Hat Bugzilla, Red Hat Advisory).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept at this time. Exploitation requires authenticated access with restore permissions, which limits the attack surface to privileged users such as administrators or course managers. The EPSS score is approximately 0.071% (0.000710), indicating a low probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. A patch has been available since February 19, 2026 (Red Hat Advisory, Red Hat Bugzilla).
moodledata, temp, or course backup directories; newly created files with unusual names or permissions following a restore operation.php, bash, curl, wget) following a restore operation.Moodle has released patched versions addressing this vulnerability: upgrade to 4.5.9 (for the 4.x branch), 5.0.5 (for the 5.0.x branch), or 5.1.2 (for the 5.1.x branch). As interim mitigations, administrators should restrict backup restore permissions to the minimum necessary set of trusted users, implement file integrity and content validation checks on backup archives before restoration, and monitor restore operations for suspicious activity. Upgrading to a patched version is the recommended and definitive remediation (Red Hat Bugzilla, Red Hat Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."