What is CVE-2026-63229?
This is a pre-authentication blind SQL injection vulnerability found in Koollab LMS. An unauthenticated attacker can exploit the SSO OAuth endpoint using time-based SQL techniques to extract sensitive database contents like PII, credentials, and valid JWT tokens. Immediate patching or mitigation is strongly recommended.
Azərbaycanca: Bu boşluq Koollab LMS-də aşkarlanan autentifikasiya öncəsi kor SQL injection zəifliyidir. Təsdiqlənməmiş hücumçu SSO OAuth endpoint-i üzərindən verilənlər bazasındakı həssas məlumatları, o cümlədən PII, etimadnamələr və JWT tokenləri oxuya bilər. Təcili şəkildə sistem yenilənməli və ya müvəqqəti azaldıcı tədbirlər tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: Koollab
FAQ2
What can an attacker obtain by exploiting the CVE-2026-63229 vulnerability in Koollab LMS?
An unauthenticated attacker can extract sensitive database contents like PII, credentials, and valid JWT tokens via the SSO OAuth endpoint.
What measures are recommended to mitigate the CVE-2026-63229 vulnerability?
Immediate patching or mitigation is strongly recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.