CVE-2026-63236
LOW
3,7
Source: 5f57b9bf-260d-4433-bf07-b6a79e9bb7d4
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: none
Availability: none
Description
AI Translation Available
An improper access control vulnerability in
Koollab LMS allowed an
unauthenticated attacker to read another user's name, internal identifier,
scores, lesson status, lesson position, and cached lesson state via the SCORM
API endpoint.
https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-094/