SQL Injection Vulnerability in ILIAS Affects Multiple Versions
CVE-2026-82538

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-82538?

ILIAS versions prior to 9.22, 10.10, and 11.3 exhibit a SQL injection vulnerability stemming from improper validation of HTTP request parameters for table sorting. This flaw permits authenticated users with write permissions to inject arbitrary SQL commands through the sort field, facilitating unauthorized database access. The exploitation of this vulnerability is exacerbated by the database layer's support for multi-statement execution, allowing attackers to execute stacked queries, which can lead to significant security breaches including database read/write access and potential administrator account takeover.

Affected Version(s)

ILIAS 9.0 < 9.22

ILIAS 10.0 < 10.10

ILIAS 11.0 < 11.3

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

André Schweigert
.