EIP-2026-109583

PRE-CVE

Moodle 3.9 - Remote Code Execution (RCE) (Authenticated)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-109583. PoCs published by lanz.

AI-analyzed exploit summary This exploit targets Moodle 3.9, leveraging authenticated RCE by escalating privileges through role manipulation and plugin installation. It requires teacher credentials or a valid session cookie to execute arbitrary commands.

Description

Moodle 3.9 - Remote Code Execution (RCE) (Authenticated)

Exploits (1)

exploitdb WORKING POC
by lanz · pythonwebappsphp
https://www.exploit-db.com/exploits/50180

This exploit targets Moodle 3.9, leveraging authenticated RCE by escalating privileges through role manipulation and plugin installation. It requires teacher credentials or a valid session cookie to execute arbitrary commands.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Moodle 3.9
Auth required
Prerequisites: Teacher credentials or valid session cookie · Course ID and manager user ID
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026