Security
Loading…

CVE-2026-86416

MEDIUMCVSS 5.4
Description

ILIAS versions before 9.23, 10.11, and 11.4 contain an authorization bypass vulnerability in ilObjGroupGUI where saveMapSettingsObject() and updateGroupTypeObject() perform state-changing operations without write permission checks. Authenticated users with only read access to a group can craft POST requests to modify group map settings and didactic template assignments, changing group modes and permissions for all members.

Timeline
Published:September 7th, 2026 1:20 PM
Last modified:September 8th, 2026 8:05 PM
CVSS Scoring

CVSS v3: 5.4 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

Weaknesses (CWE)

Source: NIST NVD · Data may lag official sources by up to one minute