---
id: CVE-2026-12789
title: A vulnerability was identified in ILIAS Learning Management System 11.0
summary: >-
  A vulnerability was identified in ILIAS Learning Management System 11.0. This
  issue affects the function ilTrQuery::executeQueries of the file
  components/ILIAS/Tracking/classes/class.ilTrQuery.php of the component
  Learning Progress Track…
severity: medium
cvss: 4.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-89
published: '2026-06-21'
updated: '2026-07-15'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-12789'
references:
  - url: 'https://vuldb.com/cve/CVE-2026-12789'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/836104'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/372531'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/372531/cti'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/836104'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00332
epssPercentile: 0.23695
ingestedAt: '2026-07-16T02:48:55.175Z'
---

## Overview

A vulnerability was identified in ILIAS Learning Management System 11.0. This issue affects the function ilTrQuery::executeQueries of the file components/ILIAS/Tracking/classes/class.ilTrQuery.php of the component Learning Progress Tracking. Such manipulation of the argument troup_table_nav leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. It is suggested to upgrade the affected component. This issue was independently identified and fixed internally by the vendor's own security team ahead of this report.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
