What is CVE-2026-63242?
A business logic vulnerability in Koollab LMS allows an authenticated learner to mark a lesson as completed via the SCORM commit endpoint without viewing the content, compromising the integrity of training and completion records. Organizations should update to the latest LMS version and review SCORM completion logic.
Azərbaycanca: Koollab LMS-də autentifikasiya olunmuş tələbəyə SCORM commit endpoint vasitəsilə dərsi izləmədən tamamlanmış statusu təyin etməyə imkan verən business logic zəifliyi aşkarlanıb. Bu, təlim və tamamlanma qeydlərinin etibarlılığını pozur. Təşkilatlar LMS-i son versiyaya yeniləməli və SCORM tamamlanma məntiqini yoxlamalıdır.
Related CVEs
link basis: shared vendor: Koollab
FAQ2
Which functionality in Koollab LMS is affected by CVE-2026-63242?
This vulnerability affects the business logic that sets lesson completion status via the SCORM commit endpoint.
What can an authenticated learner achieve by exploiting CVE-2026-63242?
They can mark a lesson as completed without viewing the content, compromising the integrity of training and completion records.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.