Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-86416

MEDIUM NVD
CVSS Score 5.4
Severity MEDIUM
Published Sep 07, 2026
Vendor unknown

Description

ILIAS versions before 9.23, 10.11, and 11.4 contain an authorization bypass vulnerability in ilObjGroupGUI where saveMapSettingsObject() and updateGroupTypeObject() perform state-changing operations without write permission checks. Authenticated users with only read access to a group can craft POST requests to modify group map settings and didactic template assignments, changing group modes and permissions for all members.

References