CVE-2026-86416

Source
https://cve.org/CVERecord?id=CVE-2026-86416
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86416.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-86416
Published
2026-09-07T12:23:54Z
Modified
2026-09-10T03:30:31Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
ILIAS before 9.23, 10.11, and 11.4 Missing Authorization in Group Object Action Methods
Details

ILIAS versions before 9.23, 10.11, and 11.4 contain an authorization bypass vulnerability in ilObjGroupGUI where saveMapSettingsObject() and updateGroupTypeObject() perform state-changing operations without write permission checks. Authenticated users with only read access to a group can craft POST requests to modify group map settings and didactic template assignments, changing group modes and permissions for all members.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-862"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86416.json"
}
References

Affected packages

Git / github.com/ilias-elearning/ilias

Affected ranges

Type
GIT
Repo
https://github.com/ilias-elearning/ilias
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "9.0"
        },
        {
            "fixed": "9.23"
        },
        {
            "introduced": "10.0"
        },
        {
            "fixed": "10.11"
        },
        {
            "introduced": "11.0"
        },
        {
            "fixed": "11.4"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v10.*
v10.0
v10.10
v10.2
v10.3
v10.4
v10.5
v10.6
v10.7
v10.8
v10.9
v11.*
v11.0
v11.1
v11.2
v11.3
v3.*
v3.8
v9.*
v9.0
v9.1
v9.10
v9.12
v9.13
v9.15
v9.16
v9.17
v9.18
v9.19
v9.20
v9.21
v9.22
v9.3
v9.4
v9.5
v9.6
v9.7
v9.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86416.json"