CVE-2026-82538
ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is passed directly into the ORDER BY clause of a SQL query without validation against declared sortable columns. Authenticated users with write permission on any container can inject arbitrary SQL through the sort parameter, and because multi-statement execution is enabled in the database layer, stacked queries enable full database read and write access as well as administrator account takeover.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.39%
- CWE
- CWE-89
- Published
- 2026-09-04
- Last modified
- 2026-09-14
Affected products
- ILIAS-eLearning e.V. ILIAS
- ILIAS-eLearning e.V. ILIAS
- ILIAS-eLearning e.V. ILIAS
Weakness type
Related vulnerabilities
- CVE-2026-76461 — Cisco Secure Email Gateway SQL Injection Vulnerability
- CVE-2026-67401 — A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTr
- CVE-2026-61667 — DIRAC: RCE in FileCatalog DatasetManager via SQL injection + eval
- CVE-2026-18658 — IBM Operational Decision Manager for Aug 2026 - Multiple CVEs addressed
- CVE-2026-9163 — SQLi in GIS Informatics' GisLab Laboratory Management System
- CVE-2026-86460 — Apache Syncope: Cypher Injection via FIQL Search on Neo4j Persistence
- CVE-2026-82232 — Apache Syncope: SQL injection via sort parameter in Task search
- CVE-2026-77051 — Apache Syncope: SQL injection via unsanitized entityKey and opEvent in Audit Events search