CVE-2026-18745: ILIAS PHP Object Injection via Shibboleth Logout
Published Sep 4, 2026
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Affected Software
1 affected component
ILIAS<9.22, <10.10, <11.3
Event History
Sep 4, 2026
CVE Published
via MITRE·05:15 PM
Rejected
via MITRE·05:15 PM
Rejected
via MITRE·05:19 PM
Data Sourced
via NVD·06:17 PM
Description
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
No authentication or user interaction is required. An attacker can use the LTI authentication endpoint to place serialized objects in session storage, then trigger deserialization through the Shibboleth back-channel logout endpoint.
2
What is the likely impact of successful exploitation?
Successful exploitation can result in arbitrary code execution as the web server user. The described technique writes attacker-controlled PHP content to a web-accessible path, enabling remote code execution.
3
Which ILIAS releases need to be remediated?
Versions before 9.22, 10.10, and 11.3 are affected. Upgrade to the applicable listed release or a later release.