What is CVE-2026-63236?
An improper access control vulnerability in Koollab LMS allows unauthenticated attackers to read other users' names, IDs, scores, lesson status and cached state via the SCORM API endpoint. Immediate access restrictions and authentication enforcement should be applied to the exposed SCORM API.
Azərbaycanca: Koollab LMS platformasında SCORM API düzgün qorunmadığı üçün (improper access control) autentifikasiya olunmamış hücumçular digər istifadəçilərin şəxsi məlumatlarını, dərs statusunu və balını oxuya bilər. Təcili olaraq SCORM API endpoint-lərinə giriş məhdudiyyəti tətbiq edilməli və autentifikasiya mexanizmi əlavə olunmalıdır.
Related CVEs
link basis: same weakness class CWE-284; shared vendor: Koollab
FAQ2
What data can an unauthenticated attacker read via the SCORM API in Koollab LMS?
An unauthenticated attacker can read other users' names, IDs, scores, lesson status and cached state.
What immediate actions should be taken to mitigate CVE-2026-63236?
Immediate access restrictions and authentication enforcement should be applied to the exposed SCORM API endpoints.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.