CVE-2026-82538: Ilias-Elearning E.v Ilias

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is passed directly into the ORDER BY clause of a SQL query without validation against declared sortable columns. Authenticated users with write permission on any container can inject arbitrary SQL through the sort parameter, and because multi-statement execution is enabled in the database layer, stacked queries enable full database read and write access as well as administrator account takeover.

Affected products

  • Ilias-Elearning E.v Ilias: from 9.0, before 9.22 (fixed in 9.22); from 10.0, before 10.10 (fixed in 10.10); from 11.0, before 11.3 (fixed in 11.3)

Published 2026-09-04. Last modified 2026-09-30.