Summary
CVE-2026-80428 is a critical unauthenticated PHP Object Injection vulnerability (CWE-502) affecting the ILIAS open-source learning management system. The flaw resides in the Shibboleth logout endpoint, which deserializes stored session data without restricting the classes that may be constructed, ultimately allowing remote code execution as the web server user. The issue carries a CVSS v3.1 base score of 9.8 (Critical) and requires no authentication or user interaction to exploit.
Technical details
- Root cause:
components/ILIAS/AuthShibboleth/resources/shib_logout.phpis exempted from authentication byilInitialisation. Its logout-notification handler reads every live session table row and passes each row’s stored data to a hand-written parser that callsunserialize()without restricting which classes may be constructed. - Trigger/precondition: An attacker can place a serialized object into a session row without logging in, because the LTI authentication entry point stores request parameters into the session and is reachable on a path exempted from authentication by the same initialisation code.
- Attack vector: Network, no privileges required, no user interaction (CVSS AV:N/AC:L/PR:N/UI:N).
- Impact: Any serialized object present in a session row is instantiated for an anonymous request, and its destructor executes when the object is discarded. A class bundled with the application writes a JSON-encoded structure to a file named by one of its own properties on destruction, letting an attacker place attacker-controlled content at an attacker-chosen path below the web root — resulting in code execution as the web server user.
Affected software
- ILIAS versions before 9.22
- ILIAS 10.0 through 10.9
- ILIAS 11.0 through 11.2
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade to ILIAS 9.22, 10.10, or 11.3, which remove the vulnerable logout-notification implementation in the Shibboleth logout endpoint.
- If immediate patching is not possible: Restrict or block external access to the Shibboleth (
shib_logout.php) and LTI authentication endpoints at the network/web-server layer until the upgrade can be applied, and monitor for unexpected file writes below the web root.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
ILIAS ... Login,Login to ILIAS,ILIAS: Login to ILIAS, ending in- ILIAS Login Page - Raw response body:
Powered by ILIAS (v<version> <date>),Login to ILIAS

