CVE-2026-107639
Deferred Deferred - Pending Action

ILIAS ImageMagick Argument Injection RCE Vulnerability

Vulnerability report for CVE-2026-107639, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

ILIAS before 9.24, 10.x before 10.12 and 11.x before 11.5 contains an argument injection vulnerability in assImagemapQuestionGUI that allows question authors to inject ImageMagick convert options via uploaded image filenames. Attackers can embed tab-separated options, which escapeshellcmd() does not neutralise, to write a PHP file under the web root and achieve remote code execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
ILIAS-eLearning e.V. ILIAS 9.0
ILIAS-eLearning e.V. ILIAS 10.0
ILIAS-eLearning e.V. ILIAS 11.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-88 The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an argument injection flaw in ILIAS versions before 9.24, 10.12, and 11.5. It exists in the assImagemapQuestionGUI component where question authors can inject ImageMagick convert options via uploaded image filenames. The function escapeshellcmd() fails to neutralize tab-separated arguments, allowing attackers to write a PHP file under the web root and achieve remote code execution.

Detection Guidance

Check ILIAS versions running on your system. Vulnerable versions are 9.0-9.23, 10.0-10.11, and 11.0-11.4. Inspect assImagemapQuestionGUI.php and assImagemapQuestion.php files for insecure filename handling. Look for user-controlled filenames passed to ImageMagick convert commands without proper sanitization.

Impact Analysis

An attacker with question author privileges could exploit this to execute arbitrary code on the server hosting ILIAS. This could lead to full system compromise, data theft, or unauthorized modifications. The impact depends on the server's configuration and the privileges of the web server user.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's security rules for protected health information. Organizations using vulnerable ILIAS versions may face compliance violations, legal penalties, and reputational damage if exploited.

Mitigation Strategies

Upgrade ILIAS to patched versions: 9.24+, 10.12+, or 11.5+. If immediate upgrade is not possible, restrict write access to web root directories and disable ImageMagick convert usage in ILIAS components. Monitor for unauthorized PHP file creation in web directories.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107639. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart