SQL Injection Vulnerability in ILIAS Affects Multiple Versions
CVE-2026-82538
8.7HIGH
What is CVE-2026-82538?
ILIAS versions prior to 9.22, 10.10, and 11.3 exhibit a SQL injection vulnerability stemming from improper validation of HTTP request parameters for table sorting. This flaw permits authenticated users with write permissions to inject arbitrary SQL commands through the sort field, facilitating unauthorized database access. The exploitation of this vulnerability is exacerbated by the database layer's support for multi-statement execution, allowing attackers to execute stacked queries, which can lead to significant security breaches including database read/write access and potential administrator account takeover.
Affected Version(s)
ILIAS 9.0 < 9.22
ILIAS 10.0 < 10.10
ILIAS 11.0 < 11.3
