Vulnerability research

Research & Advisories

I look at software that many people use and search it for bugs that are relevant to security. So far that has mostly been ILIAS – a learning platform widely used at universities and public authorities.

Whatever I find goes to the vendor first. Nothing is published until an update is available and operators have had time to install it. What meets that condition is on this page: the reported vulnerabilities with their identifiers, and the advisories that go with them.

I hold no certifications so far. Instead, you can read everything on this page for yourself and verify it with the vendor.

CVE list

reported by schweigertIT
Vulnerabilities reported by schweigertIT and the disclosure status of each
CVE ID Affected Status Advisory
CVE-2026-85135 ILIAS < 9.22 / 10.10 / 11.3 disclosed SIT-2026-004
CVE-2026-82877 ILIAS < 9.22 / 10.10 / 11.3 disclosed SIT-2026-003
CVE-2026-80428 ILIAS < 9.22 / 10.10 / 11.3 disclosed SIT-2026-002
CVE-2026-82538 ILIAS < 9.22 / 10.10 / 11.3 disclosed SIT-2026-001

All four findings are fixed, and the corresponding CVE entries are publicly available. Further reports are being coordinated with the vendors concerned.

Advisories

Status of coordinated disclosure
SIT-2026-004 disclosed · patch available

Authenticated code execution via the ILIAS Media Pool

CVE ID
CVE-2026-85135
Vendor
ILIAS open source e-Learning e.V.
Product
ILIAS 9 < 9.22, 10 < 10.10, 11 < 11.3
Weakness class
CWE-434 · no CVSS rating of its own
Published
2026-09-03, after vendor patch of 2026-08-12

The Media Pool’s subtitle upload extracted a ZIP archive unchanged into a directory served by the web server. An account with edit permission on a media object could use this to achieve code execution. Details without payloads.

Open advisory SIT-2026-004
SIT-2026-003 disclosed · patch available

Arbitrary reading of server files via the ILIAS SOAP interface

CVE ID
CVE-2026-82877
Vendor
ILIAS open source e-Learning e.V.
Product
ILIAS 9 < 9.22, 10 < 10.10, 11 < 11.3
Weakness class
CWE-22 · no CVSS rating of its own
Published
2026-09-01, after vendor patch of 2026-08-12

A base directory that was never set turned a relative path into an absolute one. Anyone allowed to create a file anywhere could use this to read arbitrary files on the server. Details without payloads.

Open advisory SIT-2026-003
SIT-2026-002 disclosed · patch available

Unauthenticated PHP object injection in the Shibboleth logout endpoint of ILIAS

CVE ID
CVE-2026-80428
Vendor
ILIAS open source e-Learning e.V.
Product
ILIAS 9 < 9.22, 10 < 10.10, 11 < 11.3
Weakness class
CWE-502 · CVSS 4.0 9.3 (Critical)
Published
2026-09-01, after vendor patch of 2026-08-12

An endpoint that requires no login deserialised stored session data without any class restriction. Code execution without an account and without user interaction. Deliberately without a step-by-step walkthrough – as much as you need to check your own installation.

Open advisory SIT-2026-002
SIT-2026-001 disclosed · patch available

SQL injection in the ILIAS repository Trash

CVE ID
CVE-2026-82538
Vendor
ILIAS open source e-Learning e.V.
Product
ILIAS 9 < 9.22, 10 < 10.10, 11 < 11.3
Weakness class
CWE-89 · CVSS 4.0 8.7 (High)
Published
2026-09-01, after vendor patch of 2026-08-12

An unvalidated sort field made its way into the ORDER BY clause. Write permission on any course was enough. Details without payloads – as much as you need to check your own installation.

Open advisory SIT-2026-001

Writeups

Series “Poking on ILIAS”

The findings come with a series of writeups: the path to the reported vulnerabilities, with approach and dead ends. The parts appear one at a time; until then, the formal details of each finding are in the corresponding advisory.

More posts coming

  1. Part 00 The test lab: one VM, every ILIAS versionSetup coming
  2. Part 01 The parameter nobody takes for inputSQL injection · CVE-2026-82538 coming
  3. Part 03 The file that is bigger than it looksAvailability coming
  4. Part 04 The path that pointed nowhereFile access · CVE-2026-82877 coming