Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-26047

22
FAUCET Score

CVE-2026-26047 describes a denial-of-service vulnerability in Moodle's TeX formula editor, affecting Moodle installations. An authenticated user can exploit insufficient execution time limits in the mimetex renderer by submitting specially crafted TeX content, leading to excessive server resource consumption and potential service interruption. Rated 6.5 Medium (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H), this vulnerability has a low attack complexity and requires user authentication, with the primary impact being high availability degradation. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.5.9CPE matchmatch criteria
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
>= 5.0.0, < 5.0.5CPE matchmatch criteria
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
>= 5.1.0, < 5.1.2CPE matchmatch criteria
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.43%
Probability of exploitation in next 30 days
EPSS Percentile
35.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0043 is in the 45th percentile among its peer group of 21,977 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (11)

boschpatch availablevia llm_extracted
Fixed in: 5.1.2, 5.0.5 and 4.5.9
View patch
composerpatch availablevia ghsa
Product: moodle/moodleFixed in: 5.1.2
composerpatch availablevia ghsa
Product: moodle/moodleFixed in: 5.0.5
composerpatch availablevia ghsa
Product: moodle/moodleFixed in: 4.5.9
gcppatch availablevia llm_extracted
Fixed in: 5.1.2, 5.0.5 and 4.5.9
View patch
haproxypatch availablevia llm_extracted
Fixed in: 5.1.2, 5.0.5 and 4.5.9
View patch
linuxpatch availablevia llm_extracted
Fixed in: 5.1.2, 5.0.5 and 4.5.9
View patch
matrixpatch availablevia llm_extracted
Fixed in: 5.1.2, 5.0.5 and 4.5.9
View patch
netgearpatch availablevia llm_extracted
Fixed in: 5.1.2, 5.0.5 and 4.5.9
View patch
snortpatch availablevia llm_extracted
Fixed in: 5.1.2, 5.0.5 and 4.5.9
View patch
vitejspatch availablevia llm_extracted
Fixed in: 5.1.2, 5.0.5 and 4.5.9
View patch

Vendor Advisories (9)

composerGHSA-cg8j-5cr2-568qmedium

Moodle TeX formula editor is vulnerable to DoS through lack of execution time limits

Feb 21, 2026
snortllm-snort-42c59628c37c3209HIGH

Denial of service risk in TeX formula editor

Jan 1, 2026
linuxllm-linux-888a6171785bd94dHIGH

Denial of service risk in TeX formula editor

Jan 1, 2026
matrixllm-matrix-e367e256a53ff848HIGH

Denial of service risk in TeX formula editor

Jan 1, 2024
haproxyllm-haproxy-07e494a913b07400HIGH

Denial of service risk in TeX formula editor

vitejsllm-vitejs-379e1741016df1a0HIGH

Denial of service risk in TeX formula editor

boschllm-bosch-b953be16229d441eHIGH

Denial of service risk in TeX formula editor

netgearllm-netgear-4b0b6df1b07655e0HIGH

Denial of service risk in TeX formula editor

gcpllm-gcp-e02beb728bf1752cHIGH

Denial of service risk in TeX formula editor

References

access.redhat.com / security/cve/CVE-2026-26047
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Third Party Advisory