SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-56877

MEDIUM · CVSS 6.3 EPSS 0.39%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The SCORM lab launch endpoint in Skillable fails to properly validate the userId parameter against the authenticated session token, allowing authenticated users to manipulate this parameter. This vulnerability enables users to bypass lab launch rate limits, potentially leading to denial of service for other users by consuming their lab allocations. Organizations utilizing Skillable for training or exams should prioritize addressing this issue to protect user access and maintain equitable resource distribution.

CVE
CVE-2026-56877
Severity
MEDIUM
CVSS
6.3
EPSS
0.39%

Original NVD Description

The SCORM lab launch endpoint in Skillable (scorm.skillable.com) through 2026-07-13 does not validate the client-supplied userId parameter against the authenticated SCORM session token. An authenticated user can substitute arbitrary userId values to bypass per-user lab launch rate limits and consume other users' lab allocations, resulting in denial of service against targeted users' lab and exam access. Skillable was formerly named Learn on Demand Systems.