What is CVE-2026-63235?
An improper access control vulnerability in Koollab LMS (CVE-2026-63235) allows an unauthenticated attacker to forcibly terminate any user's session by only knowing their email address via the login kickout endpoint, resulting in a denial of service (DoS).
Azərbaycanca: Koollab LMS-də düzgün olmayan giriş nəzarəti zəifliyi (CVE-2026-63235) autentifikasiya olunmamış hücumçuya hədəf istifadəçinin yalnız e-poçt ünvanını bilməklə onun sessiyasını məcburi şəkildə sonlandırmağa imkan verir ki, bu da xidmətə qarşı imtina (DoS) vəziyyətinə səbəb olur.
Related CVEs
link basis: same weakness class CWE-284; shared vendor: Koollab
FAQ2
What is the impact of CVE-2026-63235?
CVE-2026-63235 allows an unauthenticated attacker to forcibly terminate a target user's session by only knowing their email address, resulting in a denial of service (DoS).
Is authentication required to exploit CVE-2026-63235?
No, CVE-2026-63235 can be exploited by an unauthenticated attacker who only needs to know the target user's email address.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.