Koollab vulnerabilities
15 CVEs tracked
In our reporting, Koollab LMS is highlighted with a cluster of critical vulnerabilities spanning nine CVEs. The primary themes involve unauthenticated SQL injection (CVE-2026-63229, CVE-2026-63230) and authenticated file upload/unsafe deserialisation issues, leading to data breaches and Remote Code Execution (RCE). Specifically, unauthenticated attacks allow full database reads and JWT token theft via the SCORM report and SSO OAuth endpoints. Defenders should immediately prioritize the unauthenticated SQL injection CVEs (CVE-2026-63229, CVE-2026-63230) and scrutinize file upload mechanisms (CVE-2026-63227, CVE-2026-63228), as well as endpoints susceptible to unsafe deserialization (CVE-2026-63232, CVE-2026-63233, CVE-2026-63234) for immediate patching.
Azərbaycanca: Hesabatlarımızda Koollab LMS, kritik zəifliklər toplusu ilə diqqət mərkəzindədir. Doqquz CVE əsasən autentifikasiyasız SQL injection (CVE-2026-63229, CVE-2026-63230) və autentifikasiyalı fayl yükləmə/qeyri-seriallaşdırma (unsafe deserialisation) problemlərini əhatə edir ki, bu da məlumat sızmasına və uzaqdan kod icrasına (RCE) səbəb ola bilər. Xüsusilə, autentifikasiyasız hücumlar SCORM hesabatı və SSO OAuth endpoint-ləri vasitəsilə verilənlər bazasının tam oxunmasına və JWT token oğurluğuna imkan verir. Müdafiəçilər dərhal istismar oluna bilən autentifikasiyasız SQL injection CVE-ləri (CVE-2026-63229, CVE-2026-63230) ilə yanaşı, fayl yükləmə (CVE-2026-63227, CVE-2026-63228) və qeyri-seriallaşdırma (CVE-2026-63232, CVE-2026-63233, CVE-2026-63234) mexanizmlərinə diqqət yetirməlidir.
This vendor's CVEs15
- CVE-2026-63242EPSS 0.15%
- CVE-2026-63241EPSS 0.14%
- CVE-2026-63240EPSS 0.18%
- CVE-2026-63239EPSS 0.12%
- CVE-2026-63238EPSS 0.22%
- CVE-2026-63236EPSS 0.17%
- CVE-2026-63235EPSS 0.20%
- CVE-2026-63234EPSS 0.29%
- CVE-2026-63233EPSS 0.29%
- CVE-2026-63232EPSS 0.29%
- CVE-2026-63231EPSS 0.25%
- CVE-2026-63230EPSS 0.30%
- CVE-2026-63229EPSS 0.30%
- CVE-2026-63228EPSS 0.13%
- CVE-2026-63227EPSS 0.33%
This hub is built from skopnix's own reporting on Koollab: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.