[remote] CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22, 10.0 < 10.10, 11.0 < 11.3 - RCE
Public exploit released for CVE-2026-80428, unauthenticated PHP object injection via Shibboleth in ILIAS LMS, enabling remote code execution.
Exploit-DB entry 52682 publishes a proof-of-concept for CVE-2026-80428, an unauthenticated PHP object injection flaw in the ILIAS learning management system. The vulnerability is reachable through the Shibboleth authentication integration and can result in remote code execution. Affected versions are ILIAS below 9.22, 10.x below 10.10, and 11.x below 11.3. No evidence of in-the-wild exploitation is stated in the disclosure.
- Unauthenticated PHP object injection via the Shibboleth integration enables remote code execution in ILIAS.
- Affected versions: ILIAS below 9.22, 10.x below 10.10, and 11.x below 11.3.
- Proof-of-concept exploit published on Exploit-DB as entry 52682.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-80428 | Unauthenticated PHP Object Injection RCE in ILIAS < 9.22, 10.10, 11.3 ILIAS, an open-source learning management system, is vulnerable to an unauthenticated PHP object injection flaw (CWE-502) exploitable through the combination of its LTI authentication and Shibboleth back-channel logout endpoints. An unauthenticated attacker first injects arbitrary serialized objects into session storage via the LTI authentication endpoint, then triggers unsafe deserialization of that data through the Shibboleth back-channel logout endpoint. By chaining an available POP (property-oriented programming) gadget, the attacker can write attacker-controlled PHP content to a web-accessible path, achieving remote code execution with the privileges of the web server user. All ILIAS deployments on affected versions — prior to 9.22 on the 9.x branch, prior to 10.10 on the 10.x branch, and prior to 11.3 on the 11.x branch — are affected, with exploitation requiring no credentials or user interaction (CVSS 4.0: 9.3). As of now there is no known public proof-of-concept, it is not listed in CISA KEV, and EPSS estimates only a 0.7% chance of exploitation within 30 days, so no in-the-wild exploitation is confirmed. Do: Upgrade ILIAS to 9.22, 10.10, or 11.3 or later, depending on your branch. Where patching is delayed, restrict network or web-server access to the LTI authentication and Shibboleth back-channel logout endpoints, and audit session storage and web-accessible directories for unexpected PHP files that would indicate prior exploitation. | 9.3 | <1% |
| largeplausibly thousands of institutional LMS deployments serving hundreds of thousands of users (estimate, not a measured count) |
CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22, 10.0 < 10.10, 11.0 < 11.3 - RCE
This source does not provide full text. Read it at exploit-db.com.