Executive brief
ILIAS is a widely-used learning management system that organizations use to deliver online courses and manage educational content. The vulnerability allows authenticated users with read-only access to a group to bypass permission checks and modify group settings—including group modes and member permissions—that should only be changeable by administrators or group owners. This could lead to unauthorized changes to course structure and access controls.
Technical details
An authorization bypass exists in the ilObjGroupGUI class of ILIAS, where the saveMapSettingsObject() and updateGroupTypeObject() methods perform state-changing operations (modifying group map settings and didactic template assignments) without verifying write permissions. An authenticated attacker with read-only access to a group can craft POST requests to these endpoints to escalate privileges and modify group mode and member permission assignments. The vulnerability affects versions before 9.23, 10.11, and 11.4. Patches are available in the mentioned fixed versions.
Affected products
- ILIAS eLearning ILIAS before 9.23, 10.x before 10.11, 11.x before 11.4
Timeline
- 2026-09-07: disclosed