Pre-authentication Blind SQL Injection in Koollab LMS
CVE-2026-63229

9.1CRITICAL

Key Information:

Vendor
CVE Published:
29 July 2026

What is CVE-2026-63229?

A pre-authentication blind SQL injection vulnerability has been identified in Koollab LMS, allowing unauthenticated attackers to exploit the system through the SSO OAuth endpoint. This exploitation facilitates the use of a time-based SQL oracle for retrieving sensitive database information, including personally identifiable information (PII), user credentials, and valid JWT tokens that could potentially lead to account takeovers. Immediate remediation actions are advised to secure sensitive data and mitigate potential risks.

Affected Version(s)

Koollab LMS 5.3.2

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.