๐Ÿ” CVE Alert

CVE-2026-85135

MEDIUM 6.3

ILIAS MediaPool ZipAdapter.php uploadMultipleSubtitleFileObject unrestricted upload

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

A security flaw has been discovered in ILIAS up to 9.21/10.9/11.2. This affects the function ilObjMediaObjectGUI::uploadMultipleSubtitleFileObject of the file Services/Repository/Service/Resources/ZipAdapter.php of the component MediaPool. The manipulation results in unrestricted upload. The attack may be launched remotely. Upgrading to version 9.22, 10.10 and 11.3 is able to mitigate this issue. The patch is identified as ef5d7f99fe1ea0381db04b333a2906548b3590e4/b0d61be43671b6bfe91baf469a5ee11e764f2e23. It is recommended to upgrade the affected component.

CWE CWE-434 CWE-284
Vendor n/a
Product ilias
Published Sep 3, 2026
Last Updated Sep 3, 2026
Stay Ahead of the Next One

Get instant alerts for n/a ilias

Be the first to know when new medium vulnerabilities affecting n/a ilias are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

n/a / ILIAS
9.0 9.1 9.2 9.3 9.4 9.5 9.6 9.7 9.8 9.9 9.10 9.11 9.12 9.13 9.14 9.15 9.16 9.17 9.18 9.19 9.20 9.21 10.0 10.1 10.2 10.3 10.4 10.5 10.6 10.7 10.8 10.9 11.0 11.1 11.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/398335 vuldb.com: https://vuldb.com/vuln/398335/cti vuldb.com: https://vuldb.com/cve/CVE-2026-85135 vuldb.com: https://vuldb.com/submit/892842 github.com: https://github.com/ILIAS-eLearning/ILIAS/commit/b0d61be43671b6bfe91baf469a5ee11e764f2e23 github.com: https://github.com/ILIAS-eLearning/ILIAS/releases/tag/v11.3

Credits

๐Ÿ” andre.schweigert (VulDB User) VulDB Vulnerability Moderation Team