CVE-2026-26045
A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead to unintended execution of server-side code. Since restore capabilities are typically available to privileged users, exploitation requires authenticated access. Successful exploitation could result in full compromise of the Moodle server.
- Moodle
- < 4.5.9, 5.0.5, 5.1.2
- CVSS 3.1
- 7.2 HIGH
- EPSS
- 0.6% (43th percentile)
- Weakness
- CWE-94
- NVD status
- Analyzed
- Published
- 2026-02-21
CVE-2026-26045 at NVD
No indexed exploits for CVE-2026-26045 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-26045 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.