Posted by Muhammad Arslan Official on Sep 28 Hello, I am disclosing a vulnerability in Moodle LMS and requesting a CVE ID, as the vendor (a registered CNA) has not assigned one after coordinated disclosure, and a MITRE CNA-LR request (CAN-2026-2032565) has been under review for ~3 months without response.
Moodle LMS 3.9.2: authenticated file-upload validation bypass (CWE-434) leading to RCE under misconfiguration
About this summary. This is a short, independently written summary of an article first published by oss-security. Cyber Security News did not report or verify the underlying story. Read the original: https://seclists.org/oss-sec/2026/q3/974
Source attribution: headline and facts are from oss-security (seclists.org). Summary method: excerpt of the source description. See our source attribution policy.






