The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0.5, and 5.1.1, the Microsoft Office 365 Integration plugin local_o365 Teams SSO endpoint sso_login.php base64-decodes a JWT payload and authenticates users from the upn claim without verifying the JWT signature, allowing an unauthenticated attacker to forge a token and obtain a Moodle session as an O365-authenticated user. This issue is fixed in versions 4.5.6, 5.0.5, and 5.1.1.
Published
16 Jul 2026 16:19
Modified
16 Jul 2026 17:46
Source
CIRCL
Weaknesses (CWE)
CWE-347
References
github.com
/microsoft/o365-moodle/commit/01b2d4c2e13b06a66557527084cbf9bace655944
github.com
/microsoft/o365-moodle/commit/258872f6e2011f4efa8ebb77d2898142a9435e89
github.com
/microsoft/o365-moodle/commit/d5596655f0baaee0f11aec2e10d6f36b0bd29220
github.com
/microsoft/o365-moodle/releases/tag/v20260423_m405
github.com
/microsoft/o365-moodle/releases/tag/v20260423_m500
github.com
/microsoft/o365-moodle/releases/tag/v20260423_m501
github.com
/microsoft/o365-moodle/security/advisories/GHSA-hqjh-93qv-47v5
Affected Systems
No vendor data available.
External Links
KEV Status
Not in CISA KEV catalog