Authentication Bypass Vulnerability in Koollab LMS
CVE-2026-63238
6.5MEDIUM
What is CVE-2026-63238?
An authentication bypass vulnerability in Koollab LMS enables an unauthenticated attacker to gain control over user accounts, including administrator accounts, by providing a valid user UUID. This exploitation is possible without entering the usual primary credentials through the vulnerabilities in the 2FA validation endpoint, raising concerns about account security and access control.
Affected Version(s)
Koollab LMS 5.3.2
