CVE-2023-36485: Ilias

High severity, CVSS 7.2. EPSS: 0.8% chance of exploitation in the next 30 days.

The workflow-engine of ILIAS before 7.23 and 8 before 8.3 allows remote authenticated users to run arbitrary system commands on the application server as the application user via a malicious BPMN2 workflow definition file.

Affected products

  • Ilias Ilias: before 7.23 (fixed in 7.23); from 8.0, before 8.3 (fixed in 8.3)

Published 2023-12-25. Last modified 2026-06-17.