PT-2026-86205 · Ilias Elearning E.V. · Ilias

·

CVE-2026-82538

·

Published

2026-09-04

·

Updated

2026-09-09

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2026-82538 SQLi in ILIAS (<9.22, 10.10, 11.3) lets authenticated users with container write access inject arbitrary SQL via sort param. CVSS 8.8. Unpatched—act now. Details: https://t.co/Emh3Jd8yiK #ILIAS #valtersit #CVE #CVEAlert #infosec #SysAdmin #cybersecurity #Linux #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta #mexico #switczerland #china #france #germany #docker #kali

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82538

Affected Products

Ilias