CVE-2026-82538: Ilias-Elearning E.v Ilias
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is passed directly into the ORDER BY clause of a SQL query without validation against declared sortable columns. Authenticated users with write permission on any container can inject arbitrary SQL through the sort parameter, and because multi-statement execution is enabled in the database layer, stacked queries enable full database read and write access as well as administrator account takeover.
Affected products
- Ilias-Elearning E.v Ilias: from 9.0, before 9.22 (fixed in 9.22); from 10.0, before 10.10 (fixed in 10.10); from 11.0, before 11.3 (fixed in 11.3)
Published 2026-09-04. Last modified 2026-09-30.