Skip to content
Rota Nacional

Cyber ·

Moodle: notice highlights end of fixes for 3.9 line

A reply published on September 30, 2026 says security fixes for Moodle 3.9.x ended on December 11, 2023, and points to newer LTS versions to assess.

A reply in the oss-sec feed, published on September 30, 2026, addresses a report about a possible bypass of authenticated upload validation in Moodle 3.9.2, which could lead to remote code execution if the system is misconfigured. The text is an automatic translation; it does not detail exploitation conditions or provide a fix for the reported case.

The reply says security fixes for Moodle 3.9.x ended on December 11, 2023. It identifies Moodle LTS 4.5 as the oldest security-supported version in the 4.x line, mentions three newer versions in the 5.x line, and says LTS 5.4 was due for release that week. According to the reply, if the issue cannot be reproduced in either of the two LTS versions mentioned, there will be no fix, given the available upgrade options.

To assess risk, identify the installation's version and configuration and compare them with the original notice. Do not assume the issue affects every installation: the report refers to a configuration condition, and the reply makes its decision about a fix conditional on reproducing the issue on LTS versions.

Consult the oss-sec feed archive and the official Moodle release documentation cited in the message. Check the date, context, and original wording, since the supplied item is an automatic translation; also validate with the responsible team before planning an upgrade or configuration change.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free