Loading the current evidence view. Navigation and account controls remain available.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type cve · source NVD CVE
Grouped attempts with latest status; expand for attempt history.
13 attempts · first 2026-08-29T04:12:26.479881Z · last 2026-09-04T20:30:10.034744Z
Not listed in CISA KEV (local)
Types: cisa_kev
13 attempts · first 2026-08-29T04:12:26.485074Z · last 2026-09-04T20:30:10.042167Z
ILIAS before versions 9.22, 10.10, and 11.3 contains an unauthenticated PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting serialized objects through the LTI authentication endpoint and triggering deserialization via the Shibboleth back-channel logout endpoint. Attackers can write arbitrary serialized objects into session storage, then e
Types: nvd_local
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.