Description
An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1. An attacker can execute arbitrary code via ZIP upload.
Published: 2026-09-14
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch
AI Analysis

Impact

This vulnerability allows an attacker to execute arbitrary code by uploading a specially crafted ZIP file to the ILIAS system. The flaw stems from insufficient validation of the uploaded file paths, enabling the construction of malicious file locations that the system processes. Successful exploitation grants the attacker full control over the affected server, potentially compromising confidentiality, integrity, and availability of all data managed by the application.

Affected Systems

ILIAS product by ILIAS is affected. The vulnerable releases are ILIAS 6.23, all 7.x versions preceding 7.22, and 8.1. Any deployment running one of these versions without an upgrade is at risk.

Risk and Exploitability

The publicly disclosed CVSS score of 3.3 indicates a low severity, yet the impact type is high. The EPSS score of 0.00223 shows a very low but non‑zero probability of exploitation, and the vulnerability is not listed in CISA KEV. The likely attack vector is a web‑based file upload endpoint. Exploitation requires the attacker to deliver a specially crafted ZIP file that the system expands to unauthorized locations, leading to code execution.

Generated by OpenCVE AI on September 15, 2026 at 15:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ILIAS to a non‑vulnerable release such as version 7.22 or later, or 8.2 and above.
  • If upgrading is not immediately possible, disable the ZIP upload feature or restrict it path sanitization to prevent traversal and validate uploaded files against an allowed set of types.
  • Employ file integrity checks and ensure that uploaded archives are scanned before extraction.

Generated by OpenCVE AI on September 15, 2026 at 15:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Title ZIP Upload Arbitrary Code Execution in ILIAS

Mon, 14 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via ZIP Upload in ILIAS

Mon, 14 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via ZIP Upload in ILIAS

Mon, 14 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Description An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1. An attacker can execute arbitrary code via ZIP upload.
First Time appeared Ilias
Ilias ilias
Weaknesses CWE-23
CPEs cpe:2.3:a:ilias:ilias:*:*:*:*:*:*:*:*
Vendors & Products Ilias
Ilias ilias
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-16T14:31:49.254Z

Reserved: 2023-05-15T00:00:00.000Z

Link: CVE-2023-32778

cve-icon Vulnrichment

Updated: 2026-09-16T14:31:46.396Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T05:16:57.137

Modified: 2026-09-22T20:00:03.713

Link: CVE-2023-32778

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:00:17Z

Weaknesses
  • CWE-23

    Relative Path Traversal