Vulnerability Description
ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting serialized objects through the LTI authentication endpoint and triggering deserialization via the Shibboleth back-channel logout endpoint. Attackers can write arbitrary serialized objects into session storage, then exploit an available POP gadget through the logout endpoint's unrestricted deserialization to write attacker-controlled PHP content to a web-accessible path and achieve remote code execution as the web server user.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui&obj_id=225630&ref_
- https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui&obj_id=225631&ref_
- https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui&obj_id=225632&ref_
- https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui&cmdNode=wy:ll:6t&cmdCl
- https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui&cmdNode=wy:ll:6t&cmdCl
- https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui&cmdNode=wy:ll:6t&cmdCl
FAQ
What is CVE-2026-80428?
CVE-2026-80428 is a vulnerability with a CVSS score of 9.8 (CRITICAL). ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting serialized objec...
How severe is CVE-2026-80428?
CVE-2026-80428 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-80428?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.