Hi everyone,
I'm an ed-tech administrator at a Brazilian higher education institution (SENAI CIMATEC) and I'm trying to understand a persistent image visibility issue we experienced during a large-scale exam on May 15, 2026.
Here's the full picture:
What happened:
- We applied a quiz via New Quizzes to the entire institution simultaneously
- A significant portion of students could NOT see the images embedded in quiz questions
- A minority of students COULD see them without any issue
- Instructors could see ALL images normally, both in teacher view and student preview
- No error message was shown — just a broken image icon or blank space
- When we exported the question HTML, the <img> tags were present and the URLs looked valid
What we already tried:
- We took screenshots of the original images and re-uploaded them manually into the course
- Re-inserted the images into the questions from scratch
- This did NOT fix the problem for most students
Context:
- The exam was applied on May 15, 2026 — shortly after the Instructure security incident (May 6–11)
- We are unsure whether the incident left residual CDN/cache instability that affected file serving for student-role users specifically
- We use Classic Quizzes migrated to New Quizzes format
- No Respondus LockDown Browser was involved
Our open questions:
- Is there a known bug where re-uploading images into course Files still doesn't fix visibility for students, even when the file is published?
- Could the May 2026 security incident have caused residual CDN or permission cache issues that persisted beyond May 11?
- Why would the image URL appear valid in the HTML source but still not render for most students?
- Has anyone confirmed whether moving images to My Files (user-level, not course-level) is a reliable long-term fix or just another workaround that breaks under certain conditions?
- Is there a way via the Canvas API to audit which file URLs inside New Quizzes questions are pointing outside the current course context?
Any insight from the community — especially from admins who went through the May incident — would be hugely appreciated.
Thanks in advance!