A reply in the oss-sec feed, published on September 30, 2026, addresses a report about a possible bypass of authenticated upload validation in Moodle 3.9.2, which could lead to remote code execution if the system is misconfigured. The text is an automatic translation; it does not detail exploitation conditions or provide a fix for the reported case.
The reply says security fixes for Moodle 3.9.x ended on December 11, 2023. It identifies Moodle LTS 4.5 as the oldest security-supported version in the 4.x line, mentions three newer versions in the 5.x line, and says LTS 5.4 was due for release that week. According to the reply, if the issue cannot be reproduced in either of the two LTS versions mentioned, there will be no fix, given the available upgrade options.
To assess risk, identify the installation's version and configuration and compare them with the original notice. Do not assume the issue affects every installation: the report refers to a configuration condition, and the reply makes its decision about a fix conditional on reproducing the issue on LTS versions.
Consult the oss-sec feed archive and the official Moodle release documentation cited in the message. Check the date, context, and original wording, since the supplied item is an automatic translation; also validate with the responsible team before planning an upgrade or configuration change.