CVE-2025-67848
A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the Learning Tools Interoperability (LTI) Provider. The issue arises from the LTI authentication handlers failing to enforce the user's suspension status, enabling unauthorized access to the system. This can lead to information disclosure or other unauthorized actions by users who should be restricted.
- Moodle
- < 4.1.22, 4.4.11, 4.5.8, 5.0.4, 5.1.0
- CVSS 3.1
- 8.1 HIGH
- EPSS
- 0.4% (30th percentile)
- Weakness
- CWE-280
- NVD status
- Analyzed
- Published
- 2026-02-03
CVE-2025-67848 at NVD
No indexed exploits for CVE-2025-67848 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-67848 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.