Skip to content
Rota Nacional

Cyber ·

Report alleges Moodle 3.9.2 upload flaw

A September 28 post reports a possible file-validation bypass in Moodle 3.9.2 and requests a CVE identifier. Other versions have not been verified.

A message posted to the oss-sec feed on September 28, 2026, reports unrestricted file uploads and inadequate input validation in Moodle LMS 3.9.2. The author classifies the case as CWE-434/CWE-20 and says a CVE identifier was requested. According to the report, the vendor, described as a registered CNA, did not assign an identifier after coordinated disclosure; a request to MITRE CNA-LR, CAN-2026-2032565, had reportedly been under review for about three months without a response. These are claims in the post, not independent confirmation.

Version 3.9.2 is the only version identified as confirmed; the post says other versions have not been checked. Consult the original message in the oss-sec archive and check for updates, the vendor's analysis, and the status of the CVE request before making decisions. The available excerpt does not provide all technical details and does not establish that remote code execution occurred. If you use AI to examine the report or prepare an internal assessment, do not submit personal data, credentials, or sensitive details without authorization, and follow your organization's policy.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free