Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.7

CVE-2026-107639: ILIAS image upload can let attackers run code

CVE-2026-107639 · published 2 days ago
Summary

In older versions of the ILIAS e‑learning platform, a teacher can upload an image for a question and include special characters in the filename that the system does not properly clean. This can cause the server to create and run a malicious script, giving an attacker control of the website. Update ILIAS to the latest release (9.24, 10.12, or 11.5 and later) or apply the vendor's security patch to stop this from happening.

What to do
  • Update ilias-elearning e.v. ilias to version 9.24 or later.
Affected software
VendorProductAffected versions
ilias-elearning e.v. ilias < 9.24
Original advisory text
ILIAS before 9.24, 10.12, and 11.5 Argument Injection via Image Map Question Upload Filename
ILIAS before 9.24, 10.x before 10.12 and 11.x before 11.5 contains an argument injection vulnerability in assImagemapQuestionGUI that allows question authors to inject ImageMagick convert options via uploaded image filenames. Attackers can embed tab-separated options, which escapeshellcmd() does not neutralise, to write a PHP file under the web root and achieve remote code execution.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
8.7 High
Exploitation
<1% chance of attack within 30 days
Type
CWE-88Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
Timeline
Published8 Oct 2026
Updated10 Oct 2026
First seen8 Oct 2026
Sources
CVE-2026-107639 · MITRE
Track software like this
Free during beta