CVE-2026-54733 Details
Description
The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0.5, and 5.1.1, the Microsoft Office 365 Integration plugin local_o365 Teams SSO endpoint sso_login.php base64-decodes a JWT payload and authenticates users from the upn claim without verifying the JWT signature, allowing an unauthenticated attacker to forge a token and obtain a Moodle session as an O365-authenticated user. This issue is fixed in versions 4.5.6, 5.0.5, and 5.1.1.
A critical authentication bypass vulnerability has been identified in the Microsoft 365 and Microsoft Entra ID Plugins for Moodle, specifically within the Teams Single Sign-On (SSO) endpoint. Prior to versions 4.5.6, 5.0.5, and 5.1.1, the SSO endpoint base64-decoded JSON Web Tokens (JWT) and authenticated users based on the unverified 'upn' claim. This flaw allowed unauthenticated attackers to forge tokens and gain access to Moodle sessions as O365-authenticated users, including administrators.
Users can upgrade to Microsoft 365 and Entra ID Plugins for Moodle versions 4.5.6, 5.0.5, or 5.1.1. If an immediate upgrade is not possible, the Teams SSO feature can be disabled in the plugin settings.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-347 | Improper Verification of Cryptographic Signature | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 16, 2026 | New CVE Received | [email protected] |
| Jul 16, 2026 | CVE Modified | CISA-ADP |