Improper Access Control Vulnerability in Koollab LMS
CVE-2026-63235
3.7LOW
What is CVE-2026-63235?
An improper access control vulnerability exists in Koollab LMS, allowing an unauthenticated attacker to terminate the sessions of any user by exploiting the login kickout endpoint using only their email address. This flaw can lead to a denial of service, significantly disrupting user experience and access.
Affected Version(s)
Koollab LMS 5.3.2
