CVE-2026-30884Disclosure

LOWCVSS 9.6 · CRITICAL

Signal is active with 6 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

mdjnelson/moodle-mod_customcert is a Moodle plugin for creating dynamically generated certificates with complete customization via the web browser. Prior to versions 4.4.9 and 5.0.3, a teacher who holds `mod/customcert:manage` in any single course can read and silently overwrite certificate elements belonging to any other course in the Moodle installation. The `core_get_fragment` callback `editelement` and the `mod_customcert_save_element` web service both fail to verify that the supplied `elementid` belongs to the authorized context, enabling cross-course information disclosure and data tampering. Versions 4.4.9 and 5.0.3 fix the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • 6 total mentions across 1 day

Deep dive

Activity timeline6 mentions / 1d
02356Mentions · 2026-03-18: 6Patch / Workaround · 2026-03-18: 1Technical Details · 2026-03-18: 303-18
Signal classification3 categories
Disclosure
350.0%
General
233.3%
Patch
116.7%
Referenced assets6 URLs
Full discourse6 posts
  • CVE@CVEnew
    General

    CVE-2026-30884 mdjnelson/moodle-mod_customcert is a Moodle plugin for creating dynamically generated certificates with complete customization via the web browser. Prior to versions … https://www.cve.org/CVERecord?id=CVE-2026-30884

    Post summary

    The post merely lists CVE‑2026‑30884 for a Moodle plugin with a link to a CVE record, providing no further detail.

    00100377
    56.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-30884 Moodle CustomCert Plugin Context Bypass Vulnerability in Versions Before 4.4.9 and 5.0.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-30884

    Post summary

    The post announces CVE-2026-30884 as a context bypass vulnerability in Moodle CustomCert plugin affecting versions prior to 4.4.9 and 5.0.3, without indicating active exploitation, patches, or PoC details.

    0000054
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-30884 - Critical mdjnelson/moodle-mod_customcert is a Moodle plugin for creating dynamically generated certificates with complete customization via the web browser. Prior to versions 4.4.9 and 5.0.3, a te... https://www.thehackerwire.com/vulnerability/CVE-2026-30884/ https://t.co/AeNJizMe3E

    Post summary

    The tweet exposes a critical CVE‑2026‑30884 affecting the Moodle mod_customcert plugin, identified the vulnerable versions, and linked to external coverage for details.

    0000056
    138 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-30884 📊 Severity: 9.6 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-30884 #CVE-2026-30884 #CVE #Critical  #CyberSecurity #InfoSec https://t.co/OQWtvN6GNr

    Post summary

    The tweet simply announces a new CVE with severity information and a reference link, offering no technical or exploit details.

    0000035
    104 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-30884: CRITICAL] Moodle plugin customcert prior to versions 4.4.9 and 5.0.3 allows for unauthorized reading and overwriting of certificate elements across different courses. Update to fix this issue.#cve,CVE-2026-30884,#cybersecurity https://cvefind.com/CVE-2026-30884

    Post summary

    A critical flaw in Moodle's customcert plugin permits unauthorized read/write access to certificate data across courses; users should update to patched versions.

    0000060
    603 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-30884: mdjnelson/moodle-mod_customcert ... Moodle teachers can silently pwn any certificate across the entire installation via unchecked `elementid` parameter—cla... https://zerodaysignal.com/vulnerability/CVE-2026-30884 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑30884, noting that Moodle teachers can misuse an unchecked elementid parameter to compromise certificates across installations, but it provides no further technical, exploit, or mitigation details.

    0000058
    155 followersView on X

Explore more