Moodle 3.9.2: discussion does not confirm a CVE or exploit
A September 29, 2026 message clarifies that the oss-security mailing list does not assign CVEs and is not a way to bypass MITRE's process. The text does not, by itself, confirm an exploitable Moodle vulnerability.
A post in the oss-security feed, dated September 29, 2026, responds to a discussion whose title mentions an upload-validation bypass in Moodle LMS 3.9.2 and possible remote code execution under a misconfigured setup. The supplied text gives no technical details proving the flaw or its exploitation; its focus is the CVE assignment process.
The message clarifies that oss-security is not a CVE numbering authority. Before 2017, MITRE CNA-LR accepted requests through the list, but ended that practice in that year and directed requesters to web forms. Consult the original post and its cited reference to verify the context and current procedure; do not treat the discussion title as confirmation of a vulnerability.