Improper Access Control Vulnerability in Koollab LMS
CVE-2026-63235

3.7LOW

Key Information:

Vendor
CVE Published:
29 July 2026

What is CVE-2026-63235?

An improper access control vulnerability exists in Koollab LMS, allowing an unauthenticated attacker to terminate the sessions of any user by exploiting the login kickout endpoint using only their email address. This flaw can lead to a denial of service, significantly disrupting user experience and access.

Affected Version(s)

Koollab LMS 5.3.2

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.