CVE-2026-26047
Estado: AnalizadaMedia (6.5)—
A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimetex, insufficient execution time limits could allow specially crafted formulas to consume excessive server resources. An authenticated user could abuse this behavior to degrade performance or cause service interruption.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.58%
- Percentil entre todas las CVEs puntuadas: 46
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-400
- CWE-770
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-26047",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-26047",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-02-23T19:29:50.672029Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "patrick@puiterwijk.org",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "patrick@puiterwijk.org",
"affectedData": [
{
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "4.5.9",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.0.0",
"lessThan": "5.0.5",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.1.0",
"lessThan": "5.1.2",
"versionType": "semver"
}
],
"packageName": "moodle",
"collectionURL": "https://github.com/moodle/moodle",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-02-21T06:17:00.377",
"references": [
{
"url": "https://access.redhat.com/security/cve/CVE-2026-26047",
"tags": [
"Third Party Advisory"
],
"source": "patrick@puiterwijk.org"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2440905",
"tags": [
"Third Party Advisory"
],
"source": "patrick@puiterwijk.org"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "patrick@puiterwijk.org",
"description": [
{
"lang": "en",
"value": "CWE-400"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-770"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimetex, insufficient execution time limits could allow specially crafted formulas to consume excessive server resources. An authenticated user could abuse this behavior to degrade performance or cause service interruption."
},
{
"lang": "es",
"value": "Se ha identificado una vulnerabilidad de denegación de servicio en el editor de fórmulas TeX de Moodle. Al renderizar contenido TeX usando mimetex, si los límites de tiempo de ejecución son insuficientes, podrían permitir que fórmulas especialmente diseñadas consuman excesivos recursos del servidor. Un usuario autenticado podría abusar de este comportamiento para degradar el rendimiento o causar interrupción del servicio."
}
],
"lastModified": "2026-06-17T10:25:38.653",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "80B1995C-45EB-41E5-A497-D565964750A1",
"versionEndExcluding": "4.5.9"
},
{
"criteria": "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8CDB0968-2E2B-4C2F-BF59-9479D1EEC287",
"versionEndExcluding": "5.0.5",
"versionStartIncluding": "5.0.0"
},
{
"criteria": "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "36833D08-9C77-48B1-9240-7F326F5BB1CC",
"versionEndExcluding": "5.1.2",
"versionStartIncluding": "5.1.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "patrick@puiterwijk.org"
}