---
id: CVE-2026-82877
title: >-
  ILIAS before versions 9.22, 10.10, and 11.3 contains an arbitrary file read
  vulnerability in the SOAP addFile method that allows authenticated users to
  read server files by supplying crafted XML with COPY-mode imports
summary: >-
  ILIAS before versions 9.22, 10.10, and 11.3 contains an arbitrary file read
  vulnerability in the SOAP addFile method that allows authenticated users to
  read server files by supplying crafted XML with COPY-mode imports. Attackers
  can cons…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-22
published: '2026-08-31'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:53:23.707'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82877'
references:
  - url: >-
      https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui&obj_id=225630&ref_id=35
    label: disclosure@vulncheck.com
  - url: >-
      https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui&obj_id=225631&ref_id=35
    label: disclosure@vulncheck.com
  - url: >-
      https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui&obj_id=225632&ref_id=35
    label: disclosure@vulncheck.com
  - url: >-
      https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui&cmdNode=wy:ll:6t&cmdClass=ilBlogPostingGUI&cmd=previewFullscreen&ref_id=15821&blpg=934
    label: disclosure@vulncheck.com
  - url: >-
      https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui&cmdNode=wy:ll:6t&cmdClass=ilBlogPostingGUI&cmd=previewFullscreen&ref_id=15821&blpg=935
    label: disclosure@vulncheck.com
  - url: >-
      https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui&cmdNode=wy:ll:6t&cmdClass=ilBlogPostingGUI&cmd=previewFullscreen&ref_id=15821&blpg=936
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/ilias-arbitrary-file-read-via-soap-addfile
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00537
epssPercentile: 0.4279
ingestedAt: '2026-09-10T16:57:28.697Z'
---

## Overview

ILIAS before versions 9.22, 10.10, and 11.3 contains an arbitrary file read vulnerability in the SOAP addFile method that allows authenticated users to read server files by supplying crafted XML with COPY-mode imports. Attackers can construct absolute file paths through an unsandboxed import directory and retrieve sensitive files including configuration files containing database credentials and setup passwords.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
