CVE-2026-82877

high

Description

ILIAS versions before 9.22, 10.0 through 10.9, and 11.0 through 11.2 contain an arbitrary file read vulnerability in the SOAP addFile method that allows authenticated users to read server files by supplying crafted XML with COPY-mode imports. Attackers can construct absolute file paths through an unsandboxed import directory and retrieve sensitive files including configuration files containing database credentials and setup passwords.

References

https://www.vulncheck.com/advisories/ilias-before-9.22-arbitrary-file-read-via-soap-addfile

https://github.com/ILIAS-eLearning/ILIAS/commit/e9acd3f8d498279f6c26a145ca32ce85152496a4

https://github.com/ILIAS-eLearning/ILIAS/blob/v11.2/components/ILIAS/soap/classes/class.ilSoapFileAdministration.php#L56

https://github.com/ILIAS-eLearning/ILIAS/blob/v11.2/components/ILIAS/File/classes/class.ilFileXMLParser.php#L244

https://github.com/ILIAS-eLearning/ILIAS

Details

Source: Mitre, NVD

Published: 2026-08-31

Updated: 2026-08-31

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Severity: Medium

CVSS v4

Base Score: 7.1

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Severity: High