CVE-2026-82877 PUBLISHED

ILIAS before 9.22 Arbitrary File Read via SOAP addFile

Assigner: VulnCheck
Reserved: 31.08.2026 Published: 31.08.2026 Updated: 31.08.2026

ILIAS versions before 9.22, 10.0 through 10.9, and 11.0 through 11.2 contain an arbitrary file read vulnerability in the SOAP addFile method that allows authenticated users to read server files by supplying crafted XML with COPY-mode imports. Attackers can construct absolute file paths through an unsandboxed import directory and retrieve sensitive files including configuration files containing database credentials and setup passwords.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor ILIAS-eLearning e.V.
Product ILIAS
Versions Default: unaffected
  • affected from 0 to 9.22 (excl.)
  • affected from 10.0 to 10.10 (excl.)
  • affected from 11.0 to 11.3 (excl.)

Credits

  • André Schweigert finder

References

Problem Types

  • Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE