Improper Restriction of Excessive Authentication Attempts in Moodle - CVE-2025-62399
Published: March 26, 2026 / Updated: March 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the affected application does not limit the number of password attempts when the mobile client and auth_webservice were enabled. A remote attacker can brute force password checks against known usernames.
Affected software
Fedora
moodle
How to mitigate CVE-2025-62399
moodle - addressed in versions 4.4.11-1.fc41, 4.5.7-1.fc42, 5.0.3-1.fc43