- Description
- A flaw was found in Moodle. An authorization logic flaw, specifically due to incomplete role checks during the badge awarding process, allowed badges to be granted without proper verification. This could enable unauthorized users to obtain badges they are not entitled to, potentially leading to privilege escalation or unauthorized access to certain features.
- Source
- patrick@puiterwijk.org
- NVD status
- Modified
- Products
- moodle
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- nvd@nist.gov
- NVD-CWE-noinfo
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-863
- Hype score
- Not currently trending
A privilege escalation flaw (CVE-2025-67856) affects Moodle due to incomplete role checks in badge awarding. Update to version 5.1.1. #Moodle #InfoSec #Vulnerability https://t.co/rMhLZzB6KS
@pulsepatchio
12 Feb 2026
41 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-67856 Moodle Badge Awarding Authorization Bypass Vulnerability https://t.co/u8TryiuTT9
@VulmonFeeds
3 Feb 2026
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-67856 A flaw was found in Moodle. An authorization logic flaw, specifically due to incomplete role checks during the badge awarding process, allowed badges to be granted wi… https://t.co/NS8P0hb6Qj
@CVEnew
3 Feb 2026
150 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
"matchCriteriaId": "A2DF3FD1-3A53-41D9-890B-F6DE973AB09C",
"versionEndExcluding": "4.1.22",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
"matchCriteriaId": "73BDD52B-F279-4521-97B3-BCF12CB07384",
"versionEndExcluding": "4.4.12",
"versionStartIncluding": "4.4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
"matchCriteriaId": "C0CC5CF8-4808-41A5-B8A1-B0D6C575E5DC",
"versionEndExcluding": "4.5.8",
"versionStartIncluding": "4.5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
"matchCriteriaId": "06F81442-AEEB-483D-90A9-93DDBA5B95D6",
"versionEndExcluding": "5.0.4",
"versionStartIncluding": "5.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:moodle:moodle:5.1.0:*:*:*:*:*:*:*",
"matchCriteriaId": "6E48517A-39AA-48BA-9D79-A765E6D10519",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]