SQL Injection in ILIAS Repository Trash Table
An authenticated SQL injection vulnerability in ILIAS allows users with write permissions to execute stacked queries, leading to unauthorized database access and potential account takeover.
CVE search metadata
CVE search record: CVE-2026-82538. Severity: high. CVSS: 8.8. KEV: no. Product: ILIAS (< 9.22, < 10.10, < 11.3). Brief: SQL Injection in ILIAS Repository Trash Table. Brief link: https://feed.craftedsignal.io/briefs/2026-09-ilias-sql-injection/
ILIAS, an open-source learning management system, contains a critical SQL injection vulnerability tracked as CVE-2026-82538. The flaw exists within the repository trash table management functionality. Specifically, the system fails to validate the navigation sort field provided in HTTP requests before incorporating it into the ORDER BY clause of a database query.
Because the application enables multi-statement execution within its database abstraction layer, an attacker with write permissions on any container can leverage the sort parameter to inject stacked queries. Successful exploitation permits an attacker to perform arbitrary read and write operations against the underlying database. These actions can be used to exfiltrate sensitive data or escalate privileges by modifying administrative account credentials, effectively leading to full platform takeover. This vulnerability affects ILIAS versions prior to 9.22, 10.10, and 11.3.
Attack Chain
- Attacker authenticates to the ILIAS platform with at least write-level permissions on any repository container.
- Attacker navigates to the repository trash table interface.
- Attacker intercepts the HTTP request containing the navigation sort parameter.
- Attacker crafts a malicious payload containing stacked SQL queries, such as modifying administrative user hashes or adding a new administrative user.
- Attacker injects the payload into the sort parameter of the HTTP request.
- The application passes the unsanitized input directly into the SQL ORDER BY clause.
- The database driver executes the injected stacked queries alongside the original statement.
- Attacker gains unauthorized read/write access or elevated privileges resulting in administrator account takeover.
Impact
Successful exploitation allows authenticated attackers to bypass application-level access controls. By gaining full read and write access to the database, attackers can exfiltrate sensitive user data, modify learning content, or escalate their privileges to administrator status, resulting in total compromise of the learning management system.
Recommendation
- Upgrade ILIAS to version 9.22, 10.10, 11.3, or later immediately to remediate CVE-2026-82538.
- Audit web server logs for HTTP requests to the repository trash table containing atypical characters such as semicolons, comments, or union/select statements in the sort parameter.
- Restrict administrative and write permissions to only necessary users to reduce the blast radius of potential exploitation.
Immediate actions
Upgrade ILIAS to 9.22, 10.10, or 11.3
Deploy Sigma rule for SQL injection patterns
Mitigations
Upgrade ILIAS to 9.22 or later
CVE-2026-82538
Detection coverage 1
Detects CVE-2026-82538 Exploitation - SQL Injection via Repository Sort Parameter
highDetects attempts to exploit the SQL injection vulnerability in ILIAS by monitoring for SQL-specific characters in the sort parameter of repository requests.
Detection queries are available on the platform. Get full rules →