SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-63236

LOW · CVSS 3.7 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

An improper access control vulnerability in Koollab LMS enables unauthenticated attackers to access sensitive user information, including names, internal identifiers, and lesson statuses, through the SCORM API endpoint. While the severity is rated low, organizations using Koollab LMS should prioritize remediation to protect user privacy and prevent potential data exposure. This is particularly relevant for educational institutions and organizations relying on this learning management system.

CVE
CVE-2026-63236
Severity
LOW
CVSS
3.7
EPSS
0.17%

Original NVD Description

An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to read another user's name, internal identifier, scores, lesson status, lesson position, and cached lesson state via the SCORM API endpoint.