Impact
The vulnerability lies in the SCORM lab launch endpoint of Skillable, where the userId supplied by the client is not validated against the authenticated SCORM session token, a flaw in user‑controlled input validation (CWE‑472). An attacker who has already logged in can substitute arbitrary userId values, thereby consuming lab allocations that belong to other users and bypassing the intended per‑user launch rate limits. This misuse can exhaust a victim’s available lab or exam slots, causing a denial of service for those targeted users.
Affected Systems
Skillable’s SCORM Lab Launch Integration accessed through scorm.skillable.com is vulnerable in all versions up to 2026‑07‑13. The issue concerns specifically the lab launch endpoint that accepts a userId parameter.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate severity, reflecting the potential to disrupt service for affected users. The EPSS score is reported as less than 1%, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no public exploits have been reported. The likely attack vector is limited to authenticated users who have access to the SCORM session token; once authenticated, the bypass can be repeatedly exploited, impacting load and resource allocation for other users.
OpenCVE Enrichment