What is CVE-2026-63237?
CVE-2026-63237 is a TOTP two-factor authentication bypass vulnerability in Koollab LMS, allowing an attacker to supply a client-controlled seed to generate a matching one-time password and bypass the second authentication factor. This could potentially enable unauthorized access to administrator accounts.
Azərbaycanca: CVE-2026-63237 Koollab LMS-də TOTP iki faktorlu autentifikasiyadan yan keçmə zəifliyidir. Təcavüzkar müştəri tərəfindən idarə olunan seed dəyərini təqdim edərək uyğun birdəfəlik parol yarada və ikinci qoruma qatını keçə bilər ki, bu da administrator hesablarına icazəsiz girişə səbəb ola bilər. Təsirlənmiş sistemlərdə dərhal TOTP seed nəzarət mexanizmlərini server tərəfində yoxlamaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which system does CVE-2026-63237 affect?
CVE-2026-63237 affects the Koollab LMS system.
How can an attacker exploit CVE-2026-63237?
An attacker can exploit CVE-2026-63237 by supplying a client-controlled seed to generate a matching one-time password and bypass the TOTP two-factor authentication.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.