CVE-2026-0016
published 2026-06-01CVE-2026-0016: In updateProvidersWhenServiceRemoved of CredentialManagerService.java, there is a possible way to override settings across users due to a permissions bypass…
PriorityP411low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EPSS
0.07%
0.0th percentile
In updateProvidersWhenServiceRemoved of CredentialManagerService.java, there is a possible way to override settings across users due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-58335 moodle: Missing group access checks in grade web services [fedora-all]
bugzilla·2026-07-28
CVE-2026-58335 [MEDIUM] CVE-2026-58335 moodle: Missing group access checks in grade web services [fedora-all]
CVE-2026-58335 moodle: Missing group access checks in grade web services [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
MSA-26-0016: Missing group access checks in grade web services
Description: Missing group access checks in some grade web services
could allow a user to access grade and user information for
students in groups they did not have permission to view.
Issue summary: Missing group access checks in grade web services
Severity/Risk: Minor
Versions affected: 5.2, 5.1 to 5.1.4, 5.0 to 5.0.7, 4.5 to 4.5.11 and earlier
unsupported versions
Versions fixed: 5.2.1, 5.1.5, 5.0.8 and 4.5.12
Reporte
Bugzilla
CVE-2026-58335 moodle: Missing group access checks in grade web services
bugzilla·2026-06-30
CVE-2026-58335 [MEDIUM] CVE-2026-58335 moodle: Missing group access checks in grade web services
CVE-2026-58335 moodle: Missing group access checks in grade web services
MSA-26-0016: Missing group access checks in grade web services
Description: Missing group access checks in some grade web services
could allow a user to access grade and user information for
students in groups they did not have permission to view.
Issue summary: Missing group access checks in grade web services
Severity/Risk: Minor
Versions affected: 5.2, 5.1 to 5.1.4, 5.0 to 5.0.7, 4.5 to 4.5.11 and earlier
unsupported versions
Versions fixed: 5.2.1, 5.1.5, 5.0.8 and 4.5.12
Reported by: Paul Holden
Issue no.: MDL-88667
2026-06-01
Published