ILIAS versions before 9.23, 10.11, and 11.4 contain an authorization bypass vulnerability in ilObjGroupGUI where saveMapSettingsObject() and updateGroupTypeObject() perform state-changing operations without write permission checks. Authenticated users with only read access to a group can craft POST requests to modify group map settings and didactic template assignments, changing group modes and permissions for all members.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 07 Sep 2026 12:45:00 +0000
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-07T12:23:54.710Z
Reserved: 2026-09-07T12:12:59.349Z
Link: CVE-2026-86416
No data.
Status : Received
Published: 2026-09-07T13:20:40.233
Modified: 2026-09-07T13:20:40.233
Link: CVE-2026-86416
No data.
OpenCVE Enrichment
No data.
Weaknesses