ILIAS unauth PHP object injection RCE via Shibboleth logout (CVE-2026-80428); public exploit
CVE-2026-80428 is an unauthenticated PHP object injection in ILIAS LMS (before 9.22 / 10.10 / 11.3). NVD: attackers inject serialized objects through the LTI authentication endpoint into session storage, then trigger unrestricted deserialization via the auth-exempt Shibboleth back-channel logout endpoint (SoapServer LogoutNotification), chaining a GuzzleHttp FileCookieJar POP gadget to write attacker-controlled PHP to a web-accessible path and achieve RCE as the web server user. CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H); CVSS 4.0 9.3 Critical (VulnCheck). Fixed in ILIAS 9.22, 10.10 and 11.3 (vendor docu advisories linked from NVD). NEW 11 September 2026: Exploit-DB 52682 publishes a remote exploit (DigiProSec) for the chain; notes v9/v10 exploitable as packaged, v11.x packaged shib_logout.php may not reach the vulnerable path. Category tech (LMS stack). No Australian exploitation reports on this pass. Primary: NVD/CVE; vendor: ILIAS docu; wire: Exploit-DB.
- Product
- ILIAS e-Learning (LTI auth + Shibboleth back-channel logout)
- Versions
- Before 9.22, 10.10, and 11.3 (fixed in those builds)
- CVSS
- (CVSS 3.1); 9.3 (CVSS 4.0 Critical, VulnCheck)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Upgrade to ILIAS 9.22 / 10.10 / 11.3 or later; review Shibboleth/LTI exposure
Primary: NVD — CVE-2026-80428 · Vendor: ILIAS docu security advisory (obj 225630) · CVE: CVE-2026-80428 · Exploit-DB 52682 public exploit (11 Sep 2026)
