Insecure Direct Object Reference in Koollab LMS Exposes User Data
CVE-2026-63241

3.1LOW

Key Information:

Vendor
CVE Published:
29 July 2026

What is CVE-2026-63241?

An identified flaw in Koollab LMS allows authenticated users to access and disclose the course completion progress of other users. This vulnerability results from an insecure direct object reference, enabling unauthorized data queries that reveal sensitive learning progress information. Such exposure could lead to privacy violations and necessitate urgent mitigation measures.

Affected Version(s)

Koollab LMS 5.3.2

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.