CVE-2025-67856
A flaw was found in Moodle. An authorization logic flaw, specifically due to incomplete role checks during the badge awarding process, allowed badges to be granted without proper verification. This could enable unauthorized users to obtain badges they are not entitled to, potentially leading to privilege escalation or unauthorized access to certain features.
- Moodle
- < 4.1.22, 4.4.12, 4.5.8, 5.0.4, 5.1.0
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 0.3% (19th percentile)
- Weakness
- CWE-863
- NVD status
- Modified
- Published
- 2026-02-03
CVE-2025-67856 at NVD
No indexed exploits for CVE-2025-67856 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-67856 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.