Skip to content
ILIAS PHP Object Injection Vulnerability Enables Unauthenticated RCE

ILIAS PHP Object Injection Vulnerability Enables Unauthenticated RCE

First seen 14 Sep 2026, 02:57 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 14, 2026 at 03:35 UTC
  • CVE-2026-80428 allows unauthenticated RCE in ILIAS due to PHP object injection.
  • Affected versions include ILIAS 9.22, 10.0-10.9, and 11.0-11.2; patches are available.
  • Exploitation requires only two POST requests, posing a severe risk to server integrity.

A critical vulnerability (CVE-2026-80428) in ILIAS allows unauthenticated remote code execution via PHP object injection. Discovered by DigiProSec, the flaw affects ILIAS versions prior to 9.22, 10.0 through 10.9, and 11.0 through 11.2. The attack exploits two unauthenticated endpoints, ltiauth.php and shib_logout.php, enabling an attacker to execute arbitrary PHP code on the server. The exploit requires only two POST requests and can be executed without authentication. A working proof-of-concept (PoC) was published on September 3, 2026. The vulnerability has been confirmed to allow execution as the web server user, which poses a significant risk to sensitive data and lateral movement within networks. ILIAS has released patches in versions 9.22, 10.10, and 11.3. Security professionals are urged to apply these updates immediately.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-08-26
CVE-2026-80428 published
ILIAS vulnerability CVE-2026-80428 was officially published, detailing the unauthenticated RCE risk.
Redsecuretech
2026-09-03
First public PoC released
DigiProSec published a working proof-of-concept for exploiting the ILIAS vulnerability.
Redsecuretech
2026-09-13
Exploit details reported
Redsecuretech detailed the exploit method and impact of CVE-2026-80428, emphasizing its severity.
Redsecuretech
2026-09-14
Exploit DB entry published
Exploit DB published an entry detailing the vulnerability and its exploitation method, confirming its impact.
www.exploit-db.com

More articles in this cluster (2)

Following this threat?

Track CVE-2026-80428 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed