Description
An improper access control vulnerability in
Koollab LMS allowed an
unauthenticated attacker to read another user's name, internal identifier,
scores, lesson status, lesson position, and cached lesson state via the SCORM
API endpoint.
Published: 2026-07-29
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper access control flaw that lets an unauthenticated attacker retrieve sensitive data of other users—such as name, internal identifier, scores, lesson status, lesson position, and cached lesson state—through the SCORM API endpoint. This could potentially compromise user privacy (inferred). The weakness is identified as CWE‑284.

Affected Systems

The affected product is Koollab LMS from Three Learning. No specific version information is provided, so any deployed instance may be vulnerable until a patch is released.

Risk and Exploitability

The CVSS score of 3.7 indicates low severity, and the EPSS score of less than 1 % shows a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the flaw from any open network connection that can reach the SCORM API endpoint (likely remote network). Authentication is not required, so the endpoint can be accessed by unauthenticated users.

Generated by OpenCVE AI on August 2, 2026 at 08:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict or disable the SCORM API endpoint that reveals user data, limiting exposure to trusted users or roles only.
  • Implement strict authentication and authorization checks on the endpoint to enforce proper access control for each user.
  • Apply any vendor‑supplied security updates or patches for Koollab LMS as soon as they become available.

Generated by OpenCVE AI on August 2, 2026 at 08:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Three Learning
Three Learning koollab Lms
Weaknesses CWE-284
Vendors & Products Three Learning
Three Learning koollab Lms
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Description An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to read another user's name, internal identifier, scores, lesson status, lesson position, and cached lesson state via the SCORM API endpoint.
Title Improper access control vulnerability
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Three Learning Koollab Lms
cve-icon MITRE

Status: PUBLISHED

Assigner: CSA

Published:

Updated: 2026-07-29T14:30:56.238Z

Reserved: 2026-07-16T02:33:02.674Z

Link: CVE-2026-63236

cve-icon Vulnrichment

Updated: 2026-07-29T14:30:51.023Z

cve-icon NVD

Status : Deferred

Published: 2026-07-29T07:16:43.027

Modified: 2026-07-30T16:54:05.457

Link: CVE-2026-63236

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T08:30:12Z

Weaknesses