PatchSiren cyber security CVE debrief
CVE-2016-8643 Moodle CVE debrief
CVE-2016-8643 describes an authorization problem in Moodle’s web services layer where non-admin site managers may accidentally edit administrator accounts. The issue was publicly disclosed on 2017-01-20, and the NVD record was later modified on 2026-05-13. NVD rates the impact as medium (CVSS 3.0 4.3) with network access, low privileges, no user interaction, and integrity impact only.
- Vendor
- Moodle
- Product
- Unknown
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-20
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-20
- Advisory updated
- 2026-05-13
Who should care
Moodle administrators, security teams, and anyone operating affected Moodle 2.x or 3.x deployments should care, especially environments that delegate site-management or web-service permissions to non-admin roles.
Technical summary
NVD maps the weakness to CWE-284 (Improper Access Control) and gives the vector CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N. The vulnerable condition affects Moodle 2.x and 3.x versions listed by NVD, including versions up to 2.7.16, 2.8.x, 2.9.x, 3.0.x, and 3.1.2. The practical risk is unauthorized or unintended modification of admin accounts through web services when role boundaries are not enforced correctly.
Defensive priority
Moderate. The issue is remotely reachable and requires only low privileges, but the documented impact is limited to integrity. Prioritize it for any Moodle installation exposing web services to delegated management roles.
Recommended defensive actions
- Apply the Moodle vendor patch or update referenced in the official Moodle advisory for this issue.
- Confirm whether your deployment falls within the affected Moodle version ranges listed by NVD.
- Review web service permissions and delegated site-manager roles to ensure non-admin users cannot modify administrator accounts.
- Audit account and role changes around the disclosure window and any later suspicious edits to admin users.
- Restrict access to web services to only the minimum necessary accounts and endpoints.
- Monitor for unexpected administrative account changes and validate that current controls prevent role escalation or unintended edits.
Evidence notes
Supported by the NVD CVSS vector (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N), the CWE-284 classification, and the official/vendor references pointing to the Moodle advisory. The source corpus identifies affected Moodle 2.x/3.x versions and shows the issue is an access-control flaw rather than a code-execution or availability problem.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-8643 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-8643
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-8643 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-8643
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.