CVE-2026-82877

Source
https://cve.org/CVERecord?id=CVE-2026-82877
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82877.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-82877
Published
2026-08-31T10:51:03.778Z
Modified
2026-09-02T03:47:31.621862967Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
ILIAS before 9.22 Arbitrary File Read via SOAP addFile
Details

ILIAS versions before 9.22, 10.0 through 10.9, and 11.0 through 11.2 contain an arbitrary file read vulnerability in the SOAP addFile method that allows authenticated users to read server files by supplying crafted XML with COPY-mode imports. Attackers can construct absolute file paths through an unsandboxed import directory and retrieve sensitive files including configuration files containing database credentials and setup passwords.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82877.json",
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-22"
    ]
}
References

Affected packages

Git / github.com/ilias-elearning/ilias

Affected ranges

Type
GIT
Repo
https://github.com/ilias-elearning/ilias
Events
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "9.22"
        },
        {
            "introduced": "10.0"
        },
        {
            "fixed": "10.10"
        },
        {
            "introduced": "11.0"
        },
        {
            "fixed": "11.3"
        }
    ]
}

Affected versions

v10.*
v10.0
v10.2
v10.3
v10.4
v10.5
v10.6
v10.7
v10.8
v10.9
v11.*
v11.0
v11.1
v11.2
v3.*
v3.8
v5.*
v5.1.0beta2
v5.3.0beta1
v9.*
v9.0
v9.0_beta1
v9.0_beta3
v9.1
v9.10
v9.12
v9.13
v9.15
v9.16
v9.17
v9.18
v9.19
v9.20
v9.21
v9.3
v9.4
v9.5
v9.6
v9.7
v9.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82877.json"