What is CVE-2026-63239?
CVE-2026-63239 is a hard-coded AWS IAM credentials vulnerability in Koollab LMS. It allows attackers to access shared multi-tenant S3 buckets and SQS queues, exposing sensitive data and enabling malicious content injection, job manipulation, or email interception.
Azərbaycanca: CVE-2026-63239 Koollab LMS platformasında aşkar edilmiş 'hard-coded AWS IAM credentials' zəifliyidir. Bu boşluq təcavüzkara çox kirayəçili S3 vedrələri və SQS növbələrini ələ keçirməyə, həssas məlumatları ifşa etməyə, zərərli məzmun yeritməyə, tapşırıq manipulyasiyası və e-poçt ələ keçirməyə imkan verir.
Related CVEs
link basis: same weakness class CWE-798
FAQ2
Which AWS resources can an attacker exploiting CVE-2026-63239 gain access to?
The attacker can seize shared multi-tenant S3 buckets and SQS queues.
What are the main threats posed by CVE-2026-63239 in the Koollab LMS platform?
This vulnerability enables exposure of sensitive data, malicious content injection, job manipulation, and email interception.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.