ZeroHour
Vendor

ILIAS

1 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

[remote] CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22, 10.0 < 10.10, 11.0 < 11.3 - RCE

Public exploit released for CVE-2026-80428, unauthenticated PHP object injection via Shibboleth in ILIAS LMS, enabling remote code execution.

Exploit-DB entry 52682 publishes a proof-of-concept for CVE-2026-80428, an unauthenticated PHP object injection flaw in the ILIAS learning management system. The vulnerability is reachable through the Shibboleth authentication integration and can result in remote code execution. Affected versions are ILIAS below 9.22, 10.x below 10.10, and 11.x below 11.3. No evidence of in-the-wild exploitation is stated in the disclosure.

Exploit-DB · 4d agoExploit / PoCCVE-2026-804281

Related CVEs

  • Unauthenticated PHP Object Injection RCE in ILIAS < 9.22, 10.10, 11.3
    ILIAS, an open-source learning management system, is vulnerable to an unauthenticated PHP object injection flaw (CWE-502) exploitable through the combination of its LTI authentication and Shibboleth back-channel logout endpoints. An unauthenticated attacker first injects arbitrary serialized objects into session storage via the LTI authentication endpoint, then triggers unsafe deserialization of that data through the Shibboleth back-channel logout endpoint. By chaining an available POP (property-oriented programming) gadget, the attacker can write attacker-controlled PHP content to a web-accessible path, achieving remote code execution with the privileges of the web server user. All ILIAS deployments on affected versions — prior to 9.22 on the 9.x branch, prior to 10.10 on the 10.x branch, and prior to 11.3 on the 11.x branch — are affected, with exploitation requiring no credentials or user interaction (CVSS 4.0: 9.3). As of now there is no known public proof-of-concept, it is not listed in CISA KEV, and EPSS estimates only a 0.7% chance of exploitation within 30 days, so no in-the-wild exploitation is confirmed.
    · ILIAS 9.x before 9.22 · ILIAS 10.0 to before 10.10large

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.