Junglewise Threat Intelligence

CVE-2026-12789: ILIAS Learning Management System SQL injection in Learning Progress Tracking

CVE-2026-12789 · Severity: medium · CVSS 4.7 · Published 2026-06-21

Technologies: ILIAS eLearning e.V. ILIAS. Vendors: ILIAS eLearning e.V..

Executive brief

A security vulnerability has been identified in the ILIAS Learning Management System, a platform used for hosting online courses and tracking student progress. An attacker with high-level administrative privileges can exploit this flaw to interfere with the underlying database. This could lead to unauthorized access to sensitive information or disruption of the learning platform's operations.

Technical details

A SQL injection vulnerability exists in ILIAS Learning Management System 11.0 within the Learning Progress Tracking component. The flaw is located in the ilTrQuery::executeQueries function in the components/ILIAS/Tracking/classes/class.ilTrQuery.php file. An attacker can trigger this vulnerability by manipulating the 'troup_table_nav' argument. While the attack can be launched remotely, it requires high-level administrative privileges (PR:H). Successful exploitation allows for the execution of arbitrary SQL commands, potentially leading to data disclosure or modification. A public exploit is reportedly available, and the vendor has not yet responded to the disclosure.

Affected products

  • ILIAS Learning Management System 11.0

Timeline

  • 2026-06-21: advisory: Initial disclosure by VulDB and NVD

References