CVE-2026-54733
CRITICALmoodle-local_o365: Authentication bypass via unverified JWT signature in Teams SSO endpoint
Title source: cnaDescription
The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0.5, and 5.1.1, the Microsoft Office 365 Integration plugin local_o365 Teams SSO endpoint sso_login.php base64-decodes a JWT payload and authenticates users from the upn claim without verifying the JWT signature, allowing an unauthenticated attacker to forge a token and obtain a Moodle session as an O365-authenticated user. This issue is fixed in versions 4.5.6, 5.0.5, and 5.1.1.
References (7)
Core 7
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/microsoft/o365-moodle/security/advisories/GHSA-hqjh-93qv-47v5
X_Refsource_Misc x_refsource_misc
https://github.com/microsoft/o365-moodle/commit/01b2d4c2e13b06a66557527084cbf9bace655944
X_Refsource_Misc x_refsource_misc
https://github.com/microsoft/o365-moodle/commit/258872f6e2011f4efa8ebb77d2898142a9435e89
X_Refsource_Misc x_refsource_misc
https://github.com/microsoft/o365-moodle/commit/d5596655f0baaee0f11aec2e10d6f36b0bd29220
X_Refsource_Misc x_refsource_misc
https://github.com/microsoft/o365-moodle/releases/tag/v20260423_m405
X_Refsource_Misc x_refsource_misc
https://github.com/microsoft/o365-moodle/releases/tag/v20260423_m500
X_Refsource_Misc x_refsource_misc
https://github.com/microsoft/o365-moodle/releases/tag/v20260423_m501
Scores
CVSS v4
9.3
EPSS
0.0092
EPSS Percentile
56.6%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-347
Status
published
Products (3)
microsoft/o365-moodle
< 4.5.6
microsoft/o365-moodle
>= 5.0.0, < 5.0.5
microsoft/o365-moodle
>= 5.1.0, < 5.1.1
Published
Jul 16, 2026
Tracked Since
Jul 16, 2026