CVE-2026-80428 is an unauthenticated PHP object-injection vulnerability in ILIAS versions earlier than 9.22, 10.10, and 11.3. An attacker can supply serialized objects through the LTI authentication entry point, causing attacker-controlled serialized data to be stored in a session. The Shibboleth back-channel logout functionality subsequently deserializes stored session data without restricting constructible classes. A bundled PHP object-population gadget can execute during object destruction and write attacker-controlled PHP content beneath the web root, enabling remote code execution as the web-server user.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
The repository contains one standalone Python 3 exploit, CVE-2026-80428.py, with no external exploit framework. It targets an unauthenticated PHP object-injection chain in ILIAS: it first POSTs crafted form data to ltiauth.php, exploiting custom session-parser handling to place a serialized GuzzleHttp Cookie FileCookieJar gadget in session storage. It then POSTs a Shibboleth SOAP LogoutNotification to shib_logout.php, causing vulnerable session deserialization and invoking the gadget destructor. The destructor writes JSON containing a PHP webshell to an attacker-selected path under the ILIAS document root. The script subsequently sends commands to the generated shell using the x parameter and optionally starts an interactive command loop. The code defaults to HTTPS/443, disables TLS certificate validation, supports a custom Host header and port, and defaults to /var/www/ilias/public as the writable document root. Although metadata lists versions through 11.2, embedded notes state the packaged ILIAS 11.x logout handler is broken and that v9/v10 are the practically exploitable versions.
The repository contains one standalone Python 3 exploit, CVE-2026-80428.py, with no external exploit framework dependency. It targets an alleged unauthenticated PHP object-injection chain in ILIAS. The script POSTs a crafted form value to /ltiauth.php, using a junk| parser-confusion prefix to cause a raw serialized PHP object to be retained in a session record. It then POSTs a Shibboleth SOAP LogoutNotification to /shib_logout.php, which the exploit claims causes live session records to be unserialized without a class allowlist. Its serialized gadget chain uses ILIAS-bundled GuzzleHttp\Cookie\FileCookieJar: destructor-driven cookie-jar persistence calls file_put_contents on an attacker-selected filename. Cookie JSON embeds a compact PHP system($_GET[chr(120)]) webshell. The script creates a random util_<hex>.php filename under the configured document root, invokes it with ?x=<URL-encoded command>, parses the JSON cookie Value field for output, and can continue in an interactive command loop. HTTPS is used by default on port 443 with certificate validation explicitly disabled; non-443 ports use plain HTTP. The code is an operational RCE exploit with a basic embedded payload, rather than a detection-only script. The stated comments specifically say v9/v10 were exploitable in testing and caution that the packaged v11 logout implementation is broken.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated insecure deserialization vulnerability in ILIAS session handling. An attacker can inject serialized objects into session data via an unauthenticated LTI path; the unauthenticated Shibboleth logout-notification endpoint then deserializes session rows with unrestricted class construction. A bundled class destructor can write attacker-controlled content to an attacker-chosen location under the web root, resulting in remote code execution as the web-server user.
A critical unauthenticated PHP object-injection vulnerability in ILIAS's Shibboleth logout endpoint. An unauthenticated attacker can seed serialized data through the LTI authentication entry point; the logout handler deserializes session rows with unrestricted unserialize(), enabling a destructor gadget to write attacker-controlled content below the web root and achieve remote code execution as the web-server user.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.