{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ilias-11.x/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-80428"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ILIAS (9.x)","ILIAS (10.x)","ILIAS (11.x)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["ILIAS"],"content_html":"\u003cp\u003eILIAS, an open-source learning management system, contains a critical insecure deserialization vulnerability (CVE-2026-80428) affecting versions prior to 9.22, 10.10, and 11.3. The vulnerability resides in the Shibboleth back-channel logout-notification handler located at 'components/ILIAS/AuthShibboleth/resources/shib_logout.php'. This endpoint is improperly exempted from authentication checks. When an unauthenticated caller triggers this handler, the application iterates through all live rows in the session table and processes their stored data using an unrestricted 'unserialize()' call.\u003c/p\u003e\n\u003cp\u003eAn attacker can populate these session rows by leveraging the LTI authentication entry point, which stores request parameters into the session without requiring prior authentication. By injecting a serialized object into the session, the attacker forces the application to instantiate the object upon the call to 'unserialize()'. Through the use of application-bundled gadget chains that trigger filesystem writes upon object destruction, an attacker can write malicious code to an arbitrary location below the web root, resulting in full remote code execution as the web server user.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker identifies the LTI authentication endpoint that stores request parameters into session data without authentication.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious serialized object payload designed to trigger a filesystem write during the object's destruction phase.\u003c/li\u003e\n\u003cli\u003eThe attacker sends a crafted request to the LTI entry point, placing the malicious serialized object into a session table row.\u003c/li\u003e\n\u003cli\u003eThe attacker sends an unauthenticated HTTP request to the Shibboleth logout-notification handler ('/components/ILIAS/AuthShibboleth/resources/shib_logout.php').\u003c/li\u003e\n\u003cli\u003eThe handler retrieves the injected malicious object from the session table and passes it to the 'unserialize()' function.\u003c/li\u003e\n\u003cli\u003eThe PHP interpreter instantiates the attacker-controlled class.\u003c/li\u003e\n\u003cli\u003eThe application finishes processing the session data, leading to the destruction of the malicious object.\u003c/li\u003e\n\u003cli\u003eThe object's destructor executes, writing the attacker's payload to an arbitrary path within the web root.\u003c/li\u003e\n\u003cli\u003eThe attacker executes the newly written file via an HTTP GET request to achieve remote code execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-80428 results in complete remote code execution as the web server user. This permits the attacker to compromise the entire ILIAS instance, access stored user data, exfiltrate sensitive academic records, and potentially gain persistence on the underlying web server hosting the application.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for detection and mitigation:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of ILIAS to version 9.22, 10.10, or 11.3 immediately to remove the vulnerable logout-notification endpoint.\u003c/li\u003e\n\u003cli\u003eMonitor web access logs for requests directed at 'shib_logout.php' originating from unauthorized or external IP addresses.\u003c/li\u003e\n\u003cli\u003eImplement strict network segmentation to restrict access to LTI and Shibboleth authentication endpoints if not required for public-facing functionality.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-26T16:20:49Z","date_published":"2026-08-26T16:20:49Z","id":"https://feed.craftedsignal.io/briefs/2026-08-ilias-deserialization/","summary":"An unauthenticated remote code execution vulnerability (CVE-2026-80428) in ILIAS allows attackers to achieve arbitrary file writes and code execution by exploiting insecure deserialization within the Shibboleth logout-notification handler.","title":"Critical Unauthenticated RCE in ILIAS via Insecure Deserialization","url":"https://feed.craftedsignal.io/briefs/2026-08-ilias-deserialization/"}],"language":"en","title":"CraftedSignal Threat Feed - ILIAS (11.x)","version":"https://jsonfeed.org/version/1.1"}