CVE-2026-86416 Details
Description
ILIAS versions before 9.23, 10.11, and 11.4 contain an authorization bypass vulnerability in ilObjGroupGUI where saveMapSettingsObject() and updateGroupTypeObject() perform state-changing operations without write permission checks. Authenticated users with only read access to a group can craft POST requests to modify group map settings and didactic template assignments, changing group modes and permissions for all members.
A missing authorization vulnerability has been identified in ILIAS versions prior to 9.23, 10.11, and 11.4. The issue resides in the 'ilObjGroupGUI' component, specifically within the 'saveMapSettingsObject()' and 'updateGroupTypeObject()' methods. These methods execute state-changing operations without proper write permission checks. As a result, authenticated users with only read access to a group can send crafted POST requests to alter group map settings and didactic template assignments, thereby changing group modes and permissions for all members.
Users can upgrade to ILIAS versions 9.23, 10.11, or 11.4, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 7, 2026CISA-ADP
Assessed Sep 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ILIAS | >= 9, < 9.23 >= 10, < 10.11 >= 11, < 11.4 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 18, 2026 | CVE Modified | CISA-ADP |
| Sep 7, 2026 | New CVE Received | [email protected] |
Volerion