SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-63238

MEDIUM · CVSS 6.5 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

Koollab LMS is vulnerable to an authentication bypass that enables unauthenticated attackers to gain access to any user account, including those of administrators, by simply supplying a valid user UUID at the 2FA validation endpoint. This flaw poses a significant risk of account takeover and unauthorized access to sensitive information. Organizations using Koollab LMS should prioritize patching this vulnerability to safeguard their user accounts and prevent potential exploitation.

CVE
CVE-2026-63238
Severity
MEDIUM
CVSS
6.5
EPSS
0.22%

Original NVD Description

An authentication bypass vulnerability in Koollab LMS allowed an unauthenticated attacker to take over any account, including administrator accounts, by supplying a valid user UUID without providing primary credentials via the 2FA validation endpoint.