SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-86416

MEDIUM · CVSS 5.4 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-07 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

ILIAS versions prior to 9.23, 10.11, and 11.4 are vulnerable to an authorization bypass that allows authenticated users with read-only access to manipulate group settings and permissions through crafted POST requests. This can lead to unauthorized changes in group modes and template assignments, potentially compromising the integrity of group management. Organizations using affected ILIAS versions should prioritize patching to mitigate the risk of unauthorized access and modifications.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86416
Severity
MEDIUM
CVSS
5.4
EPSS
0.25%

Original NVD Description

ILIAS versions before 9.23, 10.11, and 11.4 contain an authorization bypass vulnerability in ilObjGroupGUI where saveMapSettingsObject() and updateGroupTypeObject() perform state-changing operations without write permission checks. Authenticated users with only read access to a group can craft POST requests to modify group map settings and didactic template assignments, changing group modes and permissions for all members.