Authenticated code execution via the ILIAS Media Pool
- CVE ID
- CVE-2026-85135
- Vendor
- ILIAS open source e-Learning e.V.
- Product
- ILIAS 9 < 9.22, 10 < 10.10, 11 < 11.3
- Weakness class
- CWE-434 · no CVSS rating of its own
- Published
- 2026-09-03, after vendor patch of 2026-08-12
The Media Pool’s subtitle upload extracted a ZIP archive unchanged into a directory served by the web server. An account with edit permission on a media object could use this to achieve code execution. Details without payloads.
Open advisory SIT-2026-004