SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-63231

HIGH · CVSS 8.1 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

A post-authentication SQL injection vulnerability in Koollab LMS allows authenticated attackers to exploit the face-to-face runs update endpoint, enabling them to read the entire application database and retrieve valid JWT tokens for account takeover. This high-severity issue poses a significant risk to organizations using Koollab LMS, particularly those with sensitive user data. Organizations should prioritize patching this vulnerability to mitigate potential data breaches and unauthorized access.

CVE
CVE-2026-63231
Severity
HIGH
CVSS
8.1
EPSS
0.25%
Oracle

Original NVD Description

A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based SQL oracle via the face-to-face runs update endpoint to read the entire application database and obtain valid JWT tokens for account takeover.