Two-Factor Authentication Bypass in Koollab LMS
CVE-2026-63237

4.8MEDIUM

Key Information:

Vendor
CVE Published:
29 July 2026

What is CVE-2026-63237?

A vulnerability in Koollab LMS allows attackers to bypass the two-factor authentication mechanism by supplying a client-controlled seed to generate valid one-time passwords. This flaw can lead to unauthorized access to administrator accounts, compromising the security of sensitive information and functionalities within the system.

Affected Version(s)

Koollab LMS 5.3.2

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.