CVE-2026-86416: ILIAS before 9.23, 10.11, and 11.4 Missing Authorization in Group Object Action Methods
ILIAS versions before 9.23, 10.11, and 11.4 contain an authorization bypass vulnerability in ilObjGroupGUI where saveMapSettingsObject() and updateGroupTypeObject() perform state-changing operations without write permission checks. Authenticated users with only read access to a group can craft POST requests to modify group map settings and didactic template assignments, changing group modes and permissions for all members.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ILIASto a version that resolves this vulnerability.Fixed in 9.23 - Upgrade
Upgrade
ILIASto a version that resolves this vulnerability.Fixed in 10.11 - Upgrade
Upgrade
ILIASto a version that resolves this vulnerability.Fixed in 11.4
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated ILIAS user who has read-only access to a group can exploit it. The issue does not require the attacker to have legitimate write permission for that group.
Is a default or unauthenticated deployment exposed?
Unauthenticated attackers are not described as able to exploit this issue. Exposure requires an account with read access to a target group.
What can a successful attacker change?
They can modify group map settings and didactic template assignments through crafted POST requests. This can change group modes and permissions affecting all group members.
Which releases need remediation?
Affected releases are ILIAS versions earlier than 9.23, 10.11, and 11.4. Updating to the applicable listed release or later addresses the affected version ranges.