PatchSiren cyber security CVE debrief
CVE-2026-85135 ILIAS eLearning CVE debrief
A security flaw has been discovered in ILIAS up to 9.21/10.9/11.2. This affects the function ilObjMediaObjectGUI::uploadMultipleSubtitleFileObject of the file Services/Repository/Service/Resources/ZipAdapter.php of the component MediaPool. The manipulation results in unrestricted upload. The attack may be launched remotely. Upgrading to version 9.22, 10.10 and 11.3 is able to mitigate this issue.
- Vendor
- ILIAS eLearning
- Product
- ILIAS
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-03
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-09-03
- Advisory updated
- 2026-09-03
Who should care
Defenders responsible for ILIAS deployments, especially those using MediaPool components in versions up to 9.21/10.9/11.2, should assess exposure and prioritize verification and potential upgrades.
Why it matters
This vulnerability allows for unrestricted file uploads in ILIAS MediaPool components. Defenders should prioritize verifying exposure, assessing upgrade feasibility, and monitoring for exploitation attempts.
- Verify exposure of ILIAS MediaPool components in versions up to 9.21/10.9/11.2
- Assess the feasibility of upgrading to patched versions 9.22, 10.10, or 11.3
- Monitor for potential exploitation attempts
Technical summary
The vulnerability affects ILIAS versions up to 9.21/10.9/11.2 in the MediaPool component. The ilObjMediaObjectGUI::uploadMultipleSubtitleFileObject function in Services/Repository/Service/Resources/ZipAdapter.php allows for unrestricted file uploads. Remote attackers can exploit this vulnerability. This vulnerability allows for unrestricted file uploads in ILIAS MediaPool components. Defenders should prioritize verifying exposure of ILIAS MediaPool components, especially in versions up to 9.21/10.9/11.2, and assess the feasibility of upgrading to patched versions 9.22, 10.10, or 11.3. The CVE record and NVD entry provide details on the vulnerability in ILIAS MediaPool. However, the scope of affected deployments and specific exploitation attempts remain unknown. The patch is identified as ef5d7f99fe1ea0381db04b333a2906548b3590e4/b0d61be43671b6bfe91baf469a5ee11e764f2e23. It is recommended to upgrade the affected component. Upgrading to version 9.22, 10.10 and 11.3 is able to mitigate this issue. The attack may be launched remotely. A security flaw has been discovered in ILIAS up to 9.21/10.9/11.2. This affects the function ilObjMediaObjectGUI::uploadMultipleSubtitleFileObject of the file Services/Repository/Service/Resources/ZipAdapter.php of the component MediaPool. The manipulation results in unrestricted upload. Defenders responsible for ILIAS deployments, especially those using MediaPool components in versions up to 9.21/10.9/11.2, should assess exposure and prioritize verification and potential upgrades. This vulnerability allows for unrestricted file uploads in ILIAS MediaPool components. Defenders should prioritize verifying exposure, assessing upgrade feasibility, and monitoring for exploitation attempts. The vulnerability affects ILIAS versions up to 9.21/10.9/11.2 in the MediaPool component. The ilObjMediaObjectGUI::uploadMultipleSubtitleFileObject function in Services/Repository/Service/Resources/ZipAdapter.php allows for unrestricted file uploads. Remote attackers can exploit this vulnerability. The patch is identified as ef5d7f99fe1ea0381db04b333a2906548b3590e4/b0d61be43671b6bfe91baf469a5ee11e764f2e23. It is recommended to upgrade the affected The il
Defensive priority
Defenders should prioritize verifying exposure of ILIAS MediaPool components, especially in versions up to 9.21/10.9/11.2, and assess the feasibility of upgrading to patched versions 9.22, 10.10, or 11.3.
Recommended defensive actions
- Verify ILIAS MediaPool component versions and assess exposure
- Evaluate the feasibility of upgrading to patched versions 9.22, 10.10, or 11.3
- Monitor for potential exploitation attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability in ILIAS MediaPool. However, the scope of affected deployments and specific exploitation attempts remain unknown. Defenders should verify exposure of ILIAS MediaPool components, especially in versions up to 9.21/10.9/11.2, assess the feasibility of upgrading to patched versions 9.22, 10.10, or 11.3, and monitor for potential exploitation attempts with limited source information.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-85135 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-85135
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-85135 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-85135
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/ILIAS-eLearning/ILIAS/commit/b0d61be43671b6bfe91baf469a5ee11e764f2e23
-
Source reference
Unverified legacy reference
URL: https://github.com/ILIAS-eLearning/ILIAS/releases/tag/v11.3
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-85135
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/892842
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/398335
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/398335/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.