Pre-authentication Blind SQL Injection in Koollab LMS
CVE-2026-63229
9.1CRITICAL
What is CVE-2026-63229?
A pre-authentication blind SQL injection vulnerability has been identified in Koollab LMS, allowing unauthenticated attackers to exploit the system through the SSO OAuth endpoint. This exploitation facilitates the use of a time-based SQL oracle for retrieving sensitive database information, including personally identifiable information (PII), user credentials, and valid JWT tokens that could potentially lead to account takeovers. Immediate remediation actions are advised to secure sensitive data and mitigate potential risks.
Affected Version(s)
Koollab LMS 5.3.2
