vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server.
| Link | Resource |
|---|---|
| https://access.redhat.com/security/cve/CVE-2026-26046 | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2440903 | Third Party Advisory |
Configuration 1 (hide)
|
26 Feb 2026, 19:46
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* | |
| First Time |
Moodle
Moodle moodle |
|
| References | () https://access.redhat.com/security/cve/CVE-2026-26046 - Third Party Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2440903 - Third Party Advisory | |
| Summary |
|
21 Feb 2026, 06:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2026-02-21 06:17
Updated : 2026-02-26 19:46
NVD link : CVE-2026-26046
Mitre link : CVE-2026-26046
CVE.ORG link : CVE-2026-26046
JSON object : View
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')