Description
ILIAS versions before 9.23, 10.11, and 11.4 contain an authorization bypass vulnerability in ilObjGroupGUI where saveMapSettingsObject() and updateGroupTypeObject() perform state-changing operations without write permission checks. Authenticated users with only read access to a group can craft POST requests to modify group map settings and didactic template assignments, changing group modes and permissions for all members.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Mon, 07 Sep 2026 12:45:00 +0000
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-07T12:23:54.710Z
Reserved: 2026-09-07T12:12:59.349Z
Link: CVE-2026-86416
No data.
Status : Received
Published: 2026-09-07T13:20:40.233
Modified: 2026-09-07T13:20:40.233
Link: CVE-2026-86416
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-862
Missing Authorization