
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26047 is a denial-of-service vulnerability in Moodle's TeX formula editor caused by insufficient execution time limits when rendering TeX content via the mimetex renderer. An authenticated user can submit specially crafted TeX formulas that cause excessive CPU consumption, leading to degraded performance or a complete service outage. Affected versions include Moodle prior to 4.5.9, 5.0.0–5.0.4 (fixed in 5.0.5), and 5.1.0–5.1.1 (fixed in 5.1.2). The vulnerability was disclosed on February 19, 2026, with a CVSS v3.1 base score of 6.5 (Medium) (Red Hat CVE, Red Hat Bugzilla).
The root cause is uncontrolled resource consumption (CWE-400) combined with allocation of resources without limits or throttling (CWE-770) in Moodle's TeX formula editor. When mimetex processes TeX input, there are no enforced execution time limits, allowing a malicious formula to monopolize CPU resources indefinitely. Exploitation requires only a low-privilege authenticated account and a network-accessible Moodle instance — no special configuration or elevated permissions are needed. No public proof-of-concept code has been identified at this time (Red Hat Bugzilla, Red Hat CVE).
Successful exploitation results in high availability impact — the Moodle server can experience severe performance degradation or a complete service outage, denying access to all platform users. There is no impact on confidentiality or integrity; the attack is purely a resource exhaustion denial-of-service. Because the attack can be triggered by any authenticated user, even low-privileged student accounts on a shared Moodle instance represent a viable threat vector (Red Hat Bugzilla, Red Hat CVE).
There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation as of the time of this report. The EPSS score is approximately 0.059%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection coverage exists via Tenable Nessus plugin 299831 (Red Hat CVE, Tenable Nessus).
/filter/tex/ or mimetex-related paths) from a single authenticated user.mimetex process on the Moodle server; multiple concurrent mimetex child processes that do not terminate in a normal timeframe.Administrators should upgrade Moodle to the patched versions: 4.5.9, 5.0.5, or 5.1.2, which enforce proper execution time limits on mimetex rendering. As interim mitigations, consider restricting access to the TeX formula editor to trusted users only (e.g., teachers or administrators), implementing rate limiting on formula submissions, and monitoring server resource usage for anomalies. Red Hat has released security updates addressing this vulnerability for affected distributions (Red Hat CVE, Red Hat Bugzilla).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."