CVE-2026-86416: ILIAS before 9.23, 10.11, and 11.4 Missing Authorization in Group Object Action Methods

Published Sep 7, 2026
·
Updated

ILIAS versions before 9.23, 10.11, and 11.4 contain an authorization bypass vulnerability in ilObjGroupGUI where saveMapSettingsObject() and updateGroupTypeObject() perform state-changing operations without write permission checks. Authenticated users with only read access to a group can craft POST requests to modify group map settings and didactic template assignments, changing group modes and permissions for all members.

Affected Software

1 affected component
ILIAS<9.23, =10.11, =11.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade ILIAS to a version that resolves this vulnerability.

    Fixed in 9.23
  2. Upgrade

    Upgrade ILIAS to a version that resolves this vulnerability.

    Fixed in 10.11
  3. Upgrade

    Upgrade ILIAS to a version that resolves this vulnerability.

    Fixed in 11.4

Event History

Sep 7, 2026
CVE Published
via MITRE·12:23 PM
Data Sourced
via MITRE·12:23 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated ILIAS user who has read-only access to a group can exploit it. The issue does not require the attacker to have legitimate write permission for that group.

2

Is a default or unauthenticated deployment exposed?

Unauthenticated attackers are not described as able to exploit this issue. Exposure requires an account with read access to a target group.

3

What can a successful attacker change?

They can modify group map settings and didactic template assignments through crafted POST requests. This can change group modes and permissions affecting all group members.

4

Which releases need remediation?

Affected releases are ILIAS versions earlier than 9.23, 10.11, and 11.4. Updating to the applicable listed release or later addresses the affected version ranges.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203