CVE-2026-63236

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
29/07/2026
Last modified:
30/07/2026

Description

An improper access control vulnerability in<br /> Koollab LMS allowed an<br /> unauthenticated attacker to read another user&amp;#39;s name, internal identifier,<br /> scores, lesson status, lesson position, and cached lesson state via the SCORM<br /> API endpoint.

References to Advisories, Solutions, and Tools