CyberRota Analysis
AI-GeneratedA vulnerability in Koollab LMS allows attackers to bypass two-factor authentication by supplying a client-controlled seed to generate a valid one-time password. This could lead to unauthorized access to administrator accounts, compromising the security of the system. Organizations using Koollab LMS should prioritize addressing this issue to protect sensitive administrative functions.
CVE
CVE-2026-63237
Severity
MEDIUM
CVSS
4.8
EPSS
0.12%
Original NVD Description
A TOTP two-factor authentication bypass vulnerability in Koollab LMS allowed an attacker to supply a client-controlled seed to generate a matching one-time password and bypass the second authentication factor, potentially enabling unauthorised access to administrator accounts.