Search

Find a vulnerability

Search criteria

    8 vulnerabilities by ILIAS-eLearning e.V.

    CVE-2026-86416 (GCVE-0-2026-86416)

    Vulnerability from nvd – Published: 2026-09-07 12:23 – Updated: 2026-09-18 17:23
    VLAI
    Title
    ILIAS before 9.23, 10.11, and 11.4 Missing Authorization in Group Object Action Methods
    Summary
    ILIAS versions before 9.23, 10.11, and 11.4 contain an authorization bypass vulnerability in ilObjGroupGUI where saveMapSettingsObject() and updateGroupTypeObject() perform state-changing operations without write permission checks. Authenticated users with only read access to a group can craft POST requests to modify group map settings and didactic template assignments, changing group modes and permissions for all members.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-18 17:08 UTC
    CWE
    Impacted products
    Vendor Product Version
    ILIAS-eLearning e.V. ILIAS Affected: 9.0 , < 9.23 (custom)
    Affected: 10.0 , < 10.11 (custom)
    Affected: 11.0 , < 11.4 (custom)
        cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*
        cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*
        cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-03 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-86416",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-18T17:08:48.596258Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-18T17:23:10.220Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://github.com/ILIAS-eLearning/ILIAS",
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/ILIAS-eLearning/ILIAS",
              "product": "ILIAS",
              "repo": "https://github.com/ILIAS-eLearning/ILIAS",
              "vendor": "ILIAS-eLearning e.V.",
              "versions": [
                {
                  "lessThan": "9.23",
                  "status": "affected",
                  "version": "9.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "10.11",
                  "status": "affected",
                  "version": "10.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "11.4",
                  "status": "affected",
                  "version": "11.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "9.23",
                      "versionStartIncluding": "9.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "10.11",
                      "versionStartIncluding": "10.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "11.4",
                      "versionStartIncluding": "11.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Siyang Wu"
            }
          ],
          "datePublic": "2026-09-03T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "ILIAS versions before 9.23, 10.11, and 11.4 contain an authorization bypass vulnerability in ilObjGroupGUI where saveMapSettingsObject() and updateGroupTypeObject() perform state-changing operations without write permission checks. Authenticated users with only read access to a group can craft POST requests to modify group map settings and didactic template assignments, changing group modes and permissions for all members."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-07T12:23:54.710Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "ILIAS 11.4 Security Advisory (Mantis 0048260)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui\u0026cmdNode=wy:ll:6t\u0026cmdClass=ilBlogPostingGUI\u0026cmd=previewFullscreen\u0026ref_id=15821\u0026blpg=942"
            },
            {
              "name": "ILIAS 10.11 Security Advisory (Mantis 0048260)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui\u0026cmdNode=wy:ll:6t\u0026cmdClass=ilBlogPostingGUI\u0026cmd=previewFullscreen\u0026ref_id=15821\u0026blpg=941"
            },
            {
              "name": "ILIAS 9.23 Security Advisory (Mantis 0048260)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui\u0026cmdNode=wy:ll:6t\u0026cmdClass=ilBlogPostingGUI\u0026cmd=previewFullscreen\u0026ref_id=15821\u0026blpg=940"
            },
            {
              "name": "Group: add missing permission checks in GUI (48260)",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/ILIAS-eLearning/ILIAS/commit/16bca712847f83440fa051cdbb15b38296357c79"
            },
            {
              "name": "ilObjGroupGUI::updateGroupTypeObject() at v11.3",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/ILIAS-eLearning/ILIAS/blob/v11.3/components/ILIAS/Group/classes/class.ilObjGroupGUI.php#L560-L569"
            },
            {
              "name": "ilObjGroupGUI::saveMapSettingsObject() at v11.3",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/ILIAS-eLearning/ILIAS/blob/v11.3/components/ILIAS/Group/classes/class.ilObjGroupGUI.php#L830-L858"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/ILIAS-eLearning/ILIAS"
            },
            {
              "name": "VulnCheck Advisory: ILIAS before 9.23, 10.11, and 11.4 Missing Authorization in Group Object Action Methods",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/ilias-before-9.23-10.11-and-11.4-missing-authorization-in-group-object-action-methods"
            }
          ],
          "title": "ILIAS before 9.23, 10.11, and 11.4 Missing Authorization in Group Object Action Methods",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-86416",
        "datePublished": "2026-09-07T12:23:54.710Z",
        "dateReserved": "2026-09-07T12:12:59.349Z",
        "dateUpdated": "2026-09-18T17:23:10.220Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-82538 (GCVE-0-2026-82538)

    Vulnerability from nvd – Published: 2026-09-04 17:37 – Updated: 2026-09-30 16:38
    VLAI
    Title
    ILIAS Arbitrary SQL Injection via Repository Trash Table Sort Parameter
    Summary
    ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is passed directly into the ORDER BY clause of a SQL query without validation against declared sortable columns. Authenticated users with write permission on any container can inject arbitrary SQL through the sort parameter, and because multi-statement execution is enabled in the database layer, stacked queries enable full database read and write access as well as administrator account takeover.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-14 19:21 UTC
    CWE
    • CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
    Impacted products
    Vendor Product Version
    ILIAS-eLearning e.V. ILIAS Affected: 9.0 , < 9.22 (custom)
    Affected: 10.0 , < 10.10 (custom)
    Affected: 11.0 , < 11.3 (custom)
        cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*
        cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*
        cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-04 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-82538",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-14T19:21:30.396053Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-14T19:33:07.855Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://github.com/ILIAS-eLearning/ILIAS",
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/ILIAS-eLearning/ILIAS",
              "product": "ILIAS",
              "repo": "https://github.com/ILIAS-eLearning/ILIAS",
              "vendor": "ILIAS-eLearning e.V.",
              "versions": [
                {
                  "lessThan": "9.22",
                  "status": "affected",
                  "version": "9.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "10.10",
                  "status": "affected",
                  "version": "10.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "11.3",
                  "status": "affected",
                  "version": "11.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "9.22",
                      "versionStartIncluding": "9.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "10.10",
                      "versionStartIncluding": "10.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "11.3",
                      "versionStartIncluding": "11.0",
                      "vulnerable": true
                    }
                  ],
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Andr\u00e9 Schweigert"
            }
          ],
          "datePublic": "2026-09-04T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is passed directly into the ORDER BY clause of a SQL query without validation against declared sortable columns. Authenticated users with write permission on any container can inject arbitrary SQL through the sort parameter, and because multi-statement execution is enabled in the database layer, stacked queries enable full database read and write access as well as administrator account takeover."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-30T16:38:25.178Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "11.3 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui\u0026cmdNode=wy:ll:6t\u0026cmdClass=ilBlogPostingGUI\u0026cmd=previewFullscreen\u0026ref_id=15821\u0026blpg=936"
            },
            {
              "name": "11.3 Download",
              "tags": [
                "product",
                "patch"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui\u0026obj_id=225632\u0026ref_id=35"
            },
            {
              "name": "10.10 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui\u0026cmdNode=wy:ll:6t\u0026cmdClass=ilBlogPostingGUI\u0026cmd=previewFullscreen\u0026ref_id=15821\u0026blpg=935"
            },
            {
              "name": "10.10 Download",
              "tags": [
                "product",
                "patch"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui\u0026obj_id=225631\u0026ref_id=35"
            },
            {
              "name": "9.22 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui\u0026cmdNode=wy:ll:6t\u0026cmdClass=ilBlogPostingGUI\u0026cmd=previewFullscreen\u0026ref_id=15821\u0026blpg=934"
            },
            {
              "name": "9.22 Download",
              "tags": [
                "product",
                "patch"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui\u0026obj_id=225630\u0026ref_id=35"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/ilias-arbitrary-sql-injection-via-repository-trash-table-sort-parameter"
            },
            {
              "name": "Researcher Advisory",
              "tags": [
                "technical-description"
              ],
              "url": "https://schweigertit.de/en/advisories/SIT-2026-001.html"
            }
          ],
          "title": "ILIAS Arbitrary SQL Injection via Repository Trash Table Sort Parameter",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-82538",
        "datePublished": "2026-09-04T17:37:16.903Z",
        "dateReserved": "2026-08-29T17:20:57.083Z",
        "dateUpdated": "2026-09-30T16:38:25.178Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-82877 (GCVE-0-2026-82877)

    Vulnerability from nvd – Published: 2026-08-31 10:51 – Updated: 2026-09-30 16:39
    VLAI
    Title
    ILIAS Arbitrary File Read via SOAP addFile
    Summary
    ILIAS before versions 9.22, 10.10, and 11.3 contains an arbitrary file read vulnerability in the SOAP addFile method that allows authenticated users to read server files by supplying crafted XML with COPY-mode imports. Attackers can construct absolute file paths through an unsandboxed import directory and retrieve sensitive files including configuration files containing database credentials and setup passwords.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-02 13:45 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    Impacted products
    Vendor Product Version
    ILIAS-eLearning e.V. ILIAS Affected: 9.0 , < 9.22 (custom)
    Affected: 10.0 , < 10.10 (custom)
    Affected: 11.0 , < 11.3 (custom)
        cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*
        cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*
        cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-01 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-82877",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-02T13:45:44.627890Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-02T13:46:18.786Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://github.com/ILIAS-eLearning/ILIAS",
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/ILIAS-eLearning/ILIAS",
              "product": "ILIAS",
              "repo": "https://github.com/ILIAS-eLearning/ILIAS",
              "vendor": "ILIAS-eLearning e.V.",
              "versions": [
                {
                  "lessThan": "9.22",
                  "status": "affected",
                  "version": "9.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "10.10",
                  "status": "affected",
                  "version": "10.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "11.3",
                  "status": "affected",
                  "version": "11.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "9.22",
                      "versionStartIncluding": "9.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "10.10",
                      "versionStartIncluding": "10.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "11.3",
                      "versionStartIncluding": "11.0",
                      "vulnerable": true
                    }
                  ],
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Andr\u00e9 Schweigert"
            }
          ],
          "datePublic": "2026-09-01T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "ILIAS before versions 9.22, 10.10, and 11.3 contains an arbitrary file read vulnerability in the SOAP addFile method that allows authenticated users to read server files by supplying crafted XML with COPY-mode imports. Attackers can construct absolute file paths through an unsandboxed import directory and retrieve sensitive files including configuration files containing database credentials and setup passwords."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-30T16:39:24.754Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "11.3 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui\u0026cmdNode=wy:ll:6t\u0026cmdClass=ilBlogPostingGUI\u0026cmd=previewFullscreen\u0026ref_id=15821\u0026blpg=936"
            },
            {
              "name": "11.3 Download",
              "tags": [
                "product",
                "patch"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui\u0026obj_id=225632\u0026ref_id=35"
            },
            {
              "name": "10.10 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui\u0026cmdNode=wy:ll:6t\u0026cmdClass=ilBlogPostingGUI\u0026cmd=previewFullscreen\u0026ref_id=15821\u0026blpg=935"
            },
            {
              "name": "10.10 Download",
              "tags": [
                "product",
                "patch"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui\u0026obj_id=225631\u0026ref_id=35"
            },
            {
              "name": "9.22 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui\u0026cmdNode=wy:ll:6t\u0026cmdClass=ilBlogPostingGUI\u0026cmd=previewFullscreen\u0026ref_id=15821\u0026blpg=934"
            },
            {
              "name": "9.22 Download",
              "tags": [
                "product",
                "patch"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui\u0026obj_id=225630\u0026ref_id=35"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/ilias-arbitrary-file-read-via-soap-addfile"
            },
            {
              "name": "Researcher Advisory",
              "tags": [
                "technical-description"
              ],
              "url": "https://schweigertit.de/en/advisories/SIT-2026-003.html"
            }
          ],
          "title": "ILIAS Arbitrary File Read via SOAP addFile",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-82877",
        "datePublished": "2026-08-31T10:51:03.778Z",
        "dateReserved": "2026-08-31T08:38:43.268Z",
        "dateUpdated": "2026-09-30T16:39:24.754Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-80428 (GCVE-0-2026-80428)

    Vulnerability from nvd – Published: 2026-08-26 15:44 – Updated: 2026-09-30 16:39
    VLAI
    Title
    ILIAS PHP Object Injection via Shibboleth Logout
    Summary
    ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting serialized objects through the LTI authentication endpoint and triggering deserialization via the Shibboleth back-channel logout endpoint. Attackers can write arbitrary serialized objects into session storage, then exploit an available POP gadget through the logout endpoint's unrestricted deserialization to write attacker-controlled PHP content to a web-accessible path and achieve remote code execution as the web server user.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-29 02:41 UTC
    CWE
    • CWE-502 - Deserialization of Untrusted Data
    Impacted products
    Vendor Product Version
    ILIAS-eLearning e.V. ILIAS Affected: 9.0 , < 9.22 (custom)
    Affected: 10.0 , < 10.10 (custom)
    Affected: 11.0 , < 11.3 (custom)
        cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*
        cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*
        cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-08-26 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-80428",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-29T02:41:22.173954Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-29T02:41:40.892Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://github.com/ILIAS-eLearning/ILIAS",
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/ILIAS-eLearning/ILIAS",
              "product": "ILIAS",
              "repo": "https://github.com/ILIAS-eLearning/ILIAS",
              "vendor": "ILIAS-eLearning e.V.",
              "versions": [
                {
                  "lessThan": "9.22",
                  "status": "affected",
                  "version": "9.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "10.10",
                  "status": "affected",
                  "version": "10.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "11.3",
                  "status": "affected",
                  "version": "11.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "9.22",
                      "versionStartIncluding": "9.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "10.10",
                      "versionStartIncluding": "10.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "11.3",
                      "versionStartIncluding": "11.0",
                      "vulnerable": true
                    }
                  ],
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Andr\u00e9 Schweigert"
            }
          ],
          "datePublic": "2026-08-26T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting serialized objects through the LTI authentication endpoint and triggering deserialization via the Shibboleth back-channel logout endpoint. Attackers can write arbitrary serialized objects into session storage, then exploit an available POP gadget through the logout endpoint\u0027s unrestricted deserialization to write attacker-controlled PHP content to a web-accessible path and achieve remote code execution as the web server user."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-502",
                  "description": "Deserialization of Untrusted Data",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-30T16:39:08.178Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "11.3 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui\u0026cmdNode=wy:ll:6t\u0026cmdClass=ilBlogPostingGUI\u0026cmd=previewFullscreen\u0026ref_id=15821\u0026blpg=936"
            },
            {
              "name": "11.3 Download",
              "tags": [
                "patch",
                "product"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui\u0026obj_id=225632\u0026ref_id=35"
            },
            {
              "name": "10.10 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui\u0026cmdNode=wy:ll:6t\u0026cmdClass=ilBlogPostingGUI\u0026cmd=previewFullscreen\u0026ref_id=15821\u0026blpg=935"
            },
            {
              "name": "10.10 Download",
              "tags": [
                "product",
                "patch"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui\u0026obj_id=225631\u0026ref_id=35"
            },
            {
              "name": "9.22 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui\u0026cmdNode=wy:ll:6t\u0026cmdClass=ilBlogPostingGUI\u0026cmd=previewFullscreen\u0026ref_id=15821\u0026blpg=934"
            },
            {
              "name": "9.22 Download",
              "tags": [
                "product",
                "patch"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui\u0026obj_id=225630\u0026ref_id=35"
            },
            {
              "name": "Researcher Advisory",
              "tags": [
                "technical-description"
              ],
              "url": "https://schweigertit.de/en/advisories/SIT-2026-002.html"
            },
            {
              "name": "Researcher Writeup",
              "tags": [
                "technical-description",
                "exploit"
              ],
              "url": "https://schweigertit.de/en/writeups/php-object-injection-shibboleth-logout.html"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "ILIAS PHP Object Injection via Shibboleth Logout",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-80428",
        "datePublished": "2026-08-26T15:44:55.917Z",
        "dateReserved": "2026-08-26T10:43:44.175Z",
        "dateUpdated": "2026-09-30T16:39:08.178Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-86416 (GCVE-0-2026-86416)

    Vulnerability from cvelistv5 – Published: 2026-09-07 12:23 – Updated: 2026-09-18 17:23
    VLAI
    Title
    ILIAS before 9.23, 10.11, and 11.4 Missing Authorization in Group Object Action Methods
    Summary
    ILIAS versions before 9.23, 10.11, and 11.4 contain an authorization bypass vulnerability in ilObjGroupGUI where saveMapSettingsObject() and updateGroupTypeObject() perform state-changing operations without write permission checks. Authenticated users with only read access to a group can craft POST requests to modify group map settings and didactic template assignments, changing group modes and permissions for all members.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-18 17:08 UTC
    CWE
    Impacted products
    Vendor Product Version
    ILIAS-eLearning e.V. ILIAS Affected: 9.0 , < 9.23 (custom)
    Affected: 10.0 , < 10.11 (custom)
    Affected: 11.0 , < 11.4 (custom)
        cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*
        cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*
        cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-03 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-86416",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-18T17:08:48.596258Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-18T17:23:10.220Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://github.com/ILIAS-eLearning/ILIAS",
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/ILIAS-eLearning/ILIAS",
              "product": "ILIAS",
              "repo": "https://github.com/ILIAS-eLearning/ILIAS",
              "vendor": "ILIAS-eLearning e.V.",
              "versions": [
                {
                  "lessThan": "9.23",
                  "status": "affected",
                  "version": "9.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "10.11",
                  "status": "affected",
                  "version": "10.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "11.4",
                  "status": "affected",
                  "version": "11.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "9.23",
                      "versionStartIncluding": "9.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "10.11",
                      "versionStartIncluding": "10.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "11.4",
                      "versionStartIncluding": "11.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Siyang Wu"
            }
          ],
          "datePublic": "2026-09-03T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "ILIAS versions before 9.23, 10.11, and 11.4 contain an authorization bypass vulnerability in ilObjGroupGUI where saveMapSettingsObject() and updateGroupTypeObject() perform state-changing operations without write permission checks. Authenticated users with only read access to a group can craft POST requests to modify group map settings and didactic template assignments, changing group modes and permissions for all members."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-07T12:23:54.710Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "ILIAS 11.4 Security Advisory (Mantis 0048260)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui\u0026cmdNode=wy:ll:6t\u0026cmdClass=ilBlogPostingGUI\u0026cmd=previewFullscreen\u0026ref_id=15821\u0026blpg=942"
            },
            {
              "name": "ILIAS 10.11 Security Advisory (Mantis 0048260)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui\u0026cmdNode=wy:ll:6t\u0026cmdClass=ilBlogPostingGUI\u0026cmd=previewFullscreen\u0026ref_id=15821\u0026blpg=941"
            },
            {
              "name": "ILIAS 9.23 Security Advisory (Mantis 0048260)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui\u0026cmdNode=wy:ll:6t\u0026cmdClass=ilBlogPostingGUI\u0026cmd=previewFullscreen\u0026ref_id=15821\u0026blpg=940"
            },
            {
              "name": "Group: add missing permission checks in GUI (48260)",
              "tags": [
                "patch"
              ],
              "url": "https://github.com/ILIAS-eLearning/ILIAS/commit/16bca712847f83440fa051cdbb15b38296357c79"
            },
            {
              "name": "ilObjGroupGUI::updateGroupTypeObject() at v11.3",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/ILIAS-eLearning/ILIAS/blob/v11.3/components/ILIAS/Group/classes/class.ilObjGroupGUI.php#L560-L569"
            },
            {
              "name": "ilObjGroupGUI::saveMapSettingsObject() at v11.3",
              "tags": [
                "technical-description"
              ],
              "url": "https://github.com/ILIAS-eLearning/ILIAS/blob/v11.3/components/ILIAS/Group/classes/class.ilObjGroupGUI.php#L830-L858"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/ILIAS-eLearning/ILIAS"
            },
            {
              "name": "VulnCheck Advisory: ILIAS before 9.23, 10.11, and 11.4 Missing Authorization in Group Object Action Methods",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/ilias-before-9.23-10.11-and-11.4-missing-authorization-in-group-object-action-methods"
            }
          ],
          "title": "ILIAS before 9.23, 10.11, and 11.4 Missing Authorization in Group Object Action Methods",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-86416",
        "datePublished": "2026-09-07T12:23:54.710Z",
        "dateReserved": "2026-09-07T12:12:59.349Z",
        "dateUpdated": "2026-09-18T17:23:10.220Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-82538 (GCVE-0-2026-82538)

    Vulnerability from cvelistv5 – Published: 2026-09-04 17:37 – Updated: 2026-09-30 16:38
    VLAI
    Title
    ILIAS Arbitrary SQL Injection via Repository Trash Table Sort Parameter
    Summary
    ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is passed directly into the ORDER BY clause of a SQL query without validation against declared sortable columns. Authenticated users with write permission on any container can inject arbitrary SQL through the sort parameter, and because multi-statement execution is enabled in the database layer, stacked queries enable full database read and write access as well as administrator account takeover.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-14 19:21 UTC
    CWE
    • CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
    Impacted products
    Vendor Product Version
    ILIAS-eLearning e.V. ILIAS Affected: 9.0 , < 9.22 (custom)
    Affected: 10.0 , < 10.10 (custom)
    Affected: 11.0 , < 11.3 (custom)
        cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*
        cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*
        cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-04 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-82538",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-14T19:21:30.396053Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-14T19:33:07.855Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://github.com/ILIAS-eLearning/ILIAS",
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/ILIAS-eLearning/ILIAS",
              "product": "ILIAS",
              "repo": "https://github.com/ILIAS-eLearning/ILIAS",
              "vendor": "ILIAS-eLearning e.V.",
              "versions": [
                {
                  "lessThan": "9.22",
                  "status": "affected",
                  "version": "9.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "10.10",
                  "status": "affected",
                  "version": "10.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "11.3",
                  "status": "affected",
                  "version": "11.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "9.22",
                      "versionStartIncluding": "9.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "10.10",
                      "versionStartIncluding": "10.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "11.3",
                      "versionStartIncluding": "11.0",
                      "vulnerable": true
                    }
                  ],
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Andr\u00e9 Schweigert"
            }
          ],
          "datePublic": "2026-09-04T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is passed directly into the ORDER BY clause of a SQL query without validation against declared sortable columns. Authenticated users with write permission on any container can inject arbitrary SQL through the sort parameter, and because multi-statement execution is enabled in the database layer, stacked queries enable full database read and write access as well as administrator account takeover."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-30T16:38:25.178Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "11.3 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui\u0026cmdNode=wy:ll:6t\u0026cmdClass=ilBlogPostingGUI\u0026cmd=previewFullscreen\u0026ref_id=15821\u0026blpg=936"
            },
            {
              "name": "11.3 Download",
              "tags": [
                "product",
                "patch"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui\u0026obj_id=225632\u0026ref_id=35"
            },
            {
              "name": "10.10 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui\u0026cmdNode=wy:ll:6t\u0026cmdClass=ilBlogPostingGUI\u0026cmd=previewFullscreen\u0026ref_id=15821\u0026blpg=935"
            },
            {
              "name": "10.10 Download",
              "tags": [
                "product",
                "patch"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui\u0026obj_id=225631\u0026ref_id=35"
            },
            {
              "name": "9.22 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui\u0026cmdNode=wy:ll:6t\u0026cmdClass=ilBlogPostingGUI\u0026cmd=previewFullscreen\u0026ref_id=15821\u0026blpg=934"
            },
            {
              "name": "9.22 Download",
              "tags": [
                "product",
                "patch"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui\u0026obj_id=225630\u0026ref_id=35"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/ilias-arbitrary-sql-injection-via-repository-trash-table-sort-parameter"
            },
            {
              "name": "Researcher Advisory",
              "tags": [
                "technical-description"
              ],
              "url": "https://schweigertit.de/en/advisories/SIT-2026-001.html"
            }
          ],
          "title": "ILIAS Arbitrary SQL Injection via Repository Trash Table Sort Parameter",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-82538",
        "datePublished": "2026-09-04T17:37:16.903Z",
        "dateReserved": "2026-08-29T17:20:57.083Z",
        "dateUpdated": "2026-09-30T16:38:25.178Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-82877 (GCVE-0-2026-82877)

    Vulnerability from cvelistv5 – Published: 2026-08-31 10:51 – Updated: 2026-09-30 16:39
    VLAI
    Title
    ILIAS Arbitrary File Read via SOAP addFile
    Summary
    ILIAS before versions 9.22, 10.10, and 11.3 contains an arbitrary file read vulnerability in the SOAP addFile method that allows authenticated users to read server files by supplying crafted XML with COPY-mode imports. Attackers can construct absolute file paths through an unsandboxed import directory and retrieve sensitive files including configuration files containing database credentials and setup passwords.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-02 13:45 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    Impacted products
    Vendor Product Version
    ILIAS-eLearning e.V. ILIAS Affected: 9.0 , < 9.22 (custom)
    Affected: 10.0 , < 10.10 (custom)
    Affected: 11.0 , < 11.3 (custom)
        cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*
        cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*
        cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-09-01 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-82877",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-02T13:45:44.627890Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-02T13:46:18.786Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://github.com/ILIAS-eLearning/ILIAS",
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/ILIAS-eLearning/ILIAS",
              "product": "ILIAS",
              "repo": "https://github.com/ILIAS-eLearning/ILIAS",
              "vendor": "ILIAS-eLearning e.V.",
              "versions": [
                {
                  "lessThan": "9.22",
                  "status": "affected",
                  "version": "9.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "10.10",
                  "status": "affected",
                  "version": "10.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "11.3",
                  "status": "affected",
                  "version": "11.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "9.22",
                      "versionStartIncluding": "9.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "10.10",
                      "versionStartIncluding": "10.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "11.3",
                      "versionStartIncluding": "11.0",
                      "vulnerable": true
                    }
                  ],
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Andr\u00e9 Schweigert"
            }
          ],
          "datePublic": "2026-09-01T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "ILIAS before versions 9.22, 10.10, and 11.3 contains an arbitrary file read vulnerability in the SOAP addFile method that allows authenticated users to read server files by supplying crafted XML with COPY-mode imports. Attackers can construct absolute file paths through an unsandboxed import directory and retrieve sensitive files including configuration files containing database credentials and setup passwords."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-30T16:39:24.754Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "11.3 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui\u0026cmdNode=wy:ll:6t\u0026cmdClass=ilBlogPostingGUI\u0026cmd=previewFullscreen\u0026ref_id=15821\u0026blpg=936"
            },
            {
              "name": "11.3 Download",
              "tags": [
                "product",
                "patch"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui\u0026obj_id=225632\u0026ref_id=35"
            },
            {
              "name": "10.10 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui\u0026cmdNode=wy:ll:6t\u0026cmdClass=ilBlogPostingGUI\u0026cmd=previewFullscreen\u0026ref_id=15821\u0026blpg=935"
            },
            {
              "name": "10.10 Download",
              "tags": [
                "product",
                "patch"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui\u0026obj_id=225631\u0026ref_id=35"
            },
            {
              "name": "9.22 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui\u0026cmdNode=wy:ll:6t\u0026cmdClass=ilBlogPostingGUI\u0026cmd=previewFullscreen\u0026ref_id=15821\u0026blpg=934"
            },
            {
              "name": "9.22 Download",
              "tags": [
                "product",
                "patch"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui\u0026obj_id=225630\u0026ref_id=35"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/ilias-arbitrary-file-read-via-soap-addfile"
            },
            {
              "name": "Researcher Advisory",
              "tags": [
                "technical-description"
              ],
              "url": "https://schweigertit.de/en/advisories/SIT-2026-003.html"
            }
          ],
          "title": "ILIAS Arbitrary File Read via SOAP addFile",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-82877",
        "datePublished": "2026-08-31T10:51:03.778Z",
        "dateReserved": "2026-08-31T08:38:43.268Z",
        "dateUpdated": "2026-09-30T16:39:24.754Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-80428 (GCVE-0-2026-80428)

    Vulnerability from cvelistv5 – Published: 2026-08-26 15:44 – Updated: 2026-09-30 16:39
    VLAI
    Title
    ILIAS PHP Object Injection via Shibboleth Logout
    Summary
    ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting serialized objects through the LTI authentication endpoint and triggering deserialization via the Shibboleth back-channel logout endpoint. Attackers can write arbitrary serialized objects into session storage, then exploit an available POP gadget through the logout endpoint's unrestricted deserialization to write attacker-controlled PHP content to a web-accessible path and achieve remote code execution as the web server user.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-29 02:41 UTC
    CWE
    • CWE-502 - Deserialization of Untrusted Data
    Impacted products
    Vendor Product Version
    ILIAS-eLearning e.V. ILIAS Affected: 9.0 , < 9.22 (custom)
    Affected: 10.0 , < 10.10 (custom)
    Affected: 11.0 , < 11.3 (custom)
        cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*
        cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*
        cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-08-26 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-80428",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-29T02:41:22.173954Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-29T02:41:40.892Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://github.com/ILIAS-eLearning/ILIAS",
              "defaultStatus": "unaffected",
              "packageURL": "pkg:github/ILIAS-eLearning/ILIAS",
              "product": "ILIAS",
              "repo": "https://github.com/ILIAS-eLearning/ILIAS",
              "vendor": "ILIAS-eLearning e.V.",
              "versions": [
                {
                  "lessThan": "9.22",
                  "status": "affected",
                  "version": "9.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "10.10",
                  "status": "affected",
                  "version": "10.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "11.3",
                  "status": "affected",
                  "version": "11.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "9.22",
                      "versionStartIncluding": "9.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "10.10",
                      "versionStartIncluding": "10.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "11.3",
                      "versionStartIncluding": "11.0",
                      "vulnerable": true
                    }
                  ],
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Andr\u00e9 Schweigert"
            }
          ],
          "datePublic": "2026-08-26T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting serialized objects through the LTI authentication endpoint and triggering deserialization via the Shibboleth back-channel logout endpoint. Attackers can write arbitrary serialized objects into session storage, then exploit an available POP gadget through the logout endpoint\u0027s unrestricted deserialization to write attacker-controlled PHP content to a web-accessible path and achieve remote code execution as the web server user."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-502",
                  "description": "Deserialization of Untrusted Data",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-30T16:39:08.178Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "11.3 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui\u0026cmdNode=wy:ll:6t\u0026cmdClass=ilBlogPostingGUI\u0026cmd=previewFullscreen\u0026ref_id=15821\u0026blpg=936"
            },
            {
              "name": "11.3 Download",
              "tags": [
                "patch",
                "product"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui\u0026obj_id=225632\u0026ref_id=35"
            },
            {
              "name": "10.10 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui\u0026cmdNode=wy:ll:6t\u0026cmdClass=ilBlogPostingGUI\u0026cmd=previewFullscreen\u0026ref_id=15821\u0026blpg=935"
            },
            {
              "name": "10.10 Download",
              "tags": [
                "product",
                "patch"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui\u0026obj_id=225631\u0026ref_id=35"
            },
            {
              "name": "9.22 Release Notes",
              "tags": [
                "release-notes"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui\u0026cmdNode=wy:ll:6t\u0026cmdClass=ilBlogPostingGUI\u0026cmd=previewFullscreen\u0026ref_id=15821\u0026blpg=934"
            },
            {
              "name": "9.22 Download",
              "tags": [
                "product",
                "patch"
              ],
              "url": "https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui\u0026obj_id=225630\u0026ref_id=35"
            },
            {
              "name": "Researcher Advisory",
              "tags": [
                "technical-description"
              ],
              "url": "https://schweigertit.de/en/advisories/SIT-2026-002.html"
            },
            {
              "name": "Researcher Writeup",
              "tags": [
                "technical-description",
                "exploit"
              ],
              "url": "https://schweigertit.de/en/writeups/php-object-injection-shibboleth-logout.html"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "ILIAS PHP Object Injection via Shibboleth Logout",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-80428",
        "datePublished": "2026-08-26T15:44:55.917Z",
        "dateReserved": "2026-08-26T10:43:44.175Z",
        "dateUpdated": "2026-09-30T16:39:08.178Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }