CVE-2026-54733

critical

Description

The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0.5, and 5.1.1, the Microsoft Office 365 Integration plugin local_o365 Teams SSO endpoint sso_login.php base64-decodes a JWT payload and authenticates users from the upn claim without verifying the JWT signature, allowing an unauthenticated attacker to forge a token and obtain a Moodle session as an O365-authenticated user. This issue is fixed in versions 4.5.6, 5.0.5, and 5.1.1.

References

https://github.com/microsoft/o365-moodle/security/advisories/GHSA-hqjh-93qv-47v5

https://github.com/microsoft/o365-moodle/releases/tag/v20260423_m501

https://github.com/microsoft/o365-moodle/releases/tag/v20260423_m500

https://github.com/microsoft/o365-moodle/releases/tag/v20260423_m405

https://github.com/microsoft/o365-moodle/commit/d5596655f0baaee0f11aec2e10d6f36b0bd29220

https://github.com/microsoft/o365-moodle/commit/258872f6e2011f4efa8ebb77d2898142a9435e89

https://github.com/microsoft/o365-moodle/commit/01b2d4c2e13b06a66557527084cbf9bace655944

Details

Source: Mitre, NVD

Published: 2026-07-16

Updated: 2026-07-16

Risk Information

CVSS v2

Base Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Severity: Medium

CVSS v4

Base Score: 9.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Severity: Critical

EPSS

EPSS: 0.00915