CVE-2026-85135
ILIAS MediaPool ZipAdapter.php uploadMultipleSubtitleFileObject unrestricted upload
CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th
A security flaw has been discovered in ILIAS up to 9.21/10.9/11.2. This affects the function ilObjMediaObjectGUI::uploadMultipleSubtitleFileObject of the file Services/Repository/Service/Resources/ZipAdapter.php of the component MediaPool. The manipulation results in unrestricted upload. The attack may be launched remotely. Upgrading to version 9.22, 10.10 and 11.3 is able to mitigate this issue. The patch is identified as ef5d7f99fe1ea0381db04b333a2906548b3590e4/b0d61be43671b6bfe91baf469a5ee11e764f2e23. It is recommended to upgrade the affected component.
| CWE | CWE-434 CWE-284 |
| Vendor | n/a |
| Product | ilias |
| Published | Sep 3, 2026 |
| Last Updated | Sep 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for n/a ilias
Be the first to know when new medium vulnerabilities affecting n/a ilias are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
n/a / ILIAS
9.0 9.1 9.2 9.3 9.4 9.5 9.6 9.7 9.8 9.9 9.10 9.11 9.12 9.13 9.14 9.15 9.16 9.17 9.18 9.19 9.20 9.21 10.0 10.1 10.2 10.3 10.4 10.5 10.6 10.7 10.8 10.9 11.0 11.1 11.2
References
vuldb.com: https://vuldb.com/vuln/398335 vuldb.com: https://vuldb.com/vuln/398335/cti vuldb.com: https://vuldb.com/cve/CVE-2026-85135 vuldb.com: https://vuldb.com/submit/892842 github.com: https://github.com/ILIAS-eLearning/ILIAS/commit/b0d61be43671b6bfe91baf469a5ee11e764f2e23 github.com: https://github.com/ILIAS-eLearning/ILIAS/releases/tag/v11.3
Credits
๐ andre.schweigert (VulDB User) VulDB Vulnerability Moderation Team