CVE-2026-80428

Source
https://cve.org/CVERecord?id=CVE-2026-80428
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80428.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80428
Published
2026-08-26T15:44:55Z
Modified
2026-09-12T03:31:06Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
ILIAS PHP Object Injection via Shibboleth Logout
Details

ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting serialized objects through the LTI authentication endpoint and triggering deserialization via the Shibboleth back-channel logout endpoint. Attackers can write arbitrary serialized objects into session storage, then exploit an available POP gadget through the logout endpoint's unrestricted deserialization to write attacker-controlled PHP content to a web-accessible path and achieve remote code execution as the web server user.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-502"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80428.json"
}
References

Affected packages

Git / github.com/ilias-elearning/ilias

Affected ranges

Type
GIT
Repo
https://github.com/ilias-elearning/ilias
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "9.0"
        },
        {
            "fixed":  "9.22"
        },
        {
            "introduced":  "10.0"
        },
        {
            "fixed":  "10.10"
        },
        {
            "introduced":  "11.0"
        },
        {
            "fixed":  "11.3"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

v10.*
v10.0
v10.2
v10.3
v10.4
v10.5
v10.6
v10.7
v10.8
v10.9
v11.*
v11.0
v11.1
v11.2
v3.*
v3.8
v9.*
v9.0
v9.1
v9.10
v9.12
v9.13
v9.15
v9.16
v9.17
v9.18
v9.19
v9.20
v9.21
v9.3
v9.4
v9.5
v9.6
v9.7
v9.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80428.json"