A message posted to the oss-sec feed on September 28, 2026, reports unrestricted file uploads and inadequate input validation in Moodle LMS 3.9.2. The author classifies the case as CWE-434/CWE-20 and says a CVE identifier was requested. According to the report, the vendor, described as a registered CNA, did not assign an identifier after coordinated disclosure; a request to MITRE CNA-LR, CAN-2026-2032565, had reportedly been under review for about three months without a response. These are claims in the post, not independent confirmation.
Version 3.9.2 is the only version identified as confirmed; the post says other versions have not been checked. Consult the original message in the oss-sec archive and check for updates, the vendor's analysis, and the status of the CVE request before making decisions. The available excerpt does not provide all technical details and does not establish that remote code execution occurred. If you use AI to examine the report or prepare an internal assessment, do not submit personal data, credentials, or sensitive details without authorization, and follow your organization's policy.