What is CVE-2026-63240?
An information disclosure vulnerability in Koollab LMS allowed an authenticated learner to retrieve correct quiz answers from the course status endpoint without completing the assessment. This compromises the integrity of the testing process. Affected users should apply the vendor-supplied patch immediately.
Azərbaycanca: Koollab LMS-də autentifikasiya olunmuş tələbəyə kurs status endpoint-i vasitəsilə quiz cavablarını qanuni yolla tamamlamadan əldə etməyə imkan verən məlumat sızması zəifliyi aşkarlanıb. Bu, qiymətləndirmə sisteminin etibarlılığını pozur. Təsirə məruz qalan istifadəçilər dərhal vendor tərəfindən təqdim olunan patchi tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
What does the CVE-2026-63240 vulnerability in Koollab LMS allow?
CVE-2026-63240 is an information disclosure vulnerability that allows an authenticated learner to retrieve correct quiz answers from the course status endpoint without completing the assessment.
What should users do to remediate the CVE-2026-63240 vulnerability?
Affected users should apply the vendor-supplied patch immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.