SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-63232

CRITICAL · CVSS 9.9 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

An authenticated attacker can exploit a SQL injection and unsafe deserialization vulnerability in Koollab LMS through the assessment reinforcement endpoint, enabling them to manipulate data passed to the unserialize() function. This could lead to the execution of arbitrary code on the server, potentially allowing the attacker to write a webshell to a publicly accessible location. Organizations using Koollab LMS should prioritize addressing this critical vulnerability to prevent unauthorized access and potential system compromise.

CVE
CVE-2026-63232
Severity
CRITICAL
CVSS
9.9
EPSS
0.29%

Original NVD Description

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcement endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and execute arbitrary code on the server.