Unrestricted File Upload Vulnerability in ILIAS eLearning Platform
CVE-2026-108113

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-108113?

The ILIAS eLearning platform suffers from an unrestricted file upload vulnerability within the QTI question import functionality. Authenticated users with question pool import rights can exploit this flaw to upload malicious files, including executable PHP scripts, to the web server. This capability can lead to remote code execution as the web server user, compromising the security and integrity of the affected system. It is crucial for administrators to apply available patches to mitigate this risk. Versions prior to 9.24, 10.12, and 11.5 are particularly susceptible.

Affected Version(s)

ILIAS 5.2.8 < 9.24

ILIAS 10.0 < 10.12

ILIAS 11.0 < 11.5

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

André Schweigert (SchweigertIT)
.