SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-63240

MEDIUM · CVSS 4.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

An information disclosure vulnerability in Koollab LMS enables authenticated learners to access correct quiz answers through the course status endpoint, undermining the integrity of assessments. This flaw poses a risk to educational institutions relying on the platform for fair evaluation processes. Organizations using Koollab LMS should prioritize remediation to protect assessment integrity and maintain academic standards.

CVE
CVE-2026-63240
Severity
MEDIUM
CVSS
4.3
EPSS
0.18%

Original NVD Description

An information disclosure vulnerability in Koollab LMS allowed an authenticated learner to obtain correct quiz answers from the course status endpoint without completing the assessment legitimately, compromising the integrity of assessments.