CVE-2026-82877

Source
https://cve.org/CVERecord?id=CVE-2026-82877
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82877.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-82877
Published
2026-08-31T10:51:03Z
Modified
2026-09-12T03:30:28Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
ILIAS Arbitrary File Read via SOAP addFile
Details

ILIAS before versions 9.22, 10.10, and 11.3 contains an arbitrary file read vulnerability in the SOAP addFile method that allows authenticated users to read server files by supplying crafted XML with COPY-mode imports. Attackers can construct absolute file paths through an unsandboxed import directory and retrieve sensitive files including configuration files containing database credentials and setup passwords.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-22"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82877.json"
}
References

Affected packages

Git / github.com/ilias-elearning/ilias

Affected ranges

Type
GIT
Repo
https://github.com/ilias-elearning/ilias
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "9.0"
        },
        {
            "fixed":  "9.22"
        },
        {
            "introduced":  "10.0"
        },
        {
            "fixed":  "10.10"
        },
        {
            "introduced":  "11.0"
        },
        {
            "fixed":  "11.3"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

v10.*
v10.0
v10.2
v10.3
v10.4
v10.5
v10.6
v10.7
v10.8
v10.9
v11.*
v11.0
v11.1
v11.2
v3.*
v3.8
v9.*
v9.0
v9.1
v9.10
v9.12
v9.13
v9.15
v9.16
v9.17
v9.18
v9.19
v9.20
v9.21
v9.3
v9.4
v9.5
v9.6
v9.7
v9.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82877.json"