Description
An authentication bypass vulnerability in Koollab LMS allowed an unauthenticated
attacker to take over any account, including administrator accounts, by
supplying a valid user UUID without providing primary credentials via the 2FA
validation endpoint.
Published: 2026-07-29
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an authentication bypass that permits an unauthenticated attacker to take control of any account, including administrators, by submitting a valid user UUID to the 2FA validation endpoint without supplying primary credentials. This flaw arises from insufficient validation of authentication context and is classified as CWE‑287, an authentication bypass. An attacker can thereby gain full access to target accounts, compromising confidentiality, integrity, and availability.

Affected Systems

The flaw affects Koollab Learning Management System by Three Learning. The CVE description does not specify affected versions, so all current releases are potentially vulnerable until a vendor patch is released.

Risk and Exploitability

The CVSS base score of 6.5 indicates a medium severity vulnerability. The EPSS score is below 1%, implying a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, which reduces urgency for immediate remediation. The attack vector appears to be unauthenticated access to the 2FA validation endpoint; an attacker only needs to know a valid user UUID, which could be obtained via enumeration or prior compromise. Given these constraints the overall risk is moderate yet significant, warranting prompt mitigation.

Generated by OpenCVE AI on August 2, 2026 at 08:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install any public patch from Three Learning that fixes the authentication bypass flaw for Koollab LMS.
  • Restrict access to the 2FA validation endpoint so it can be invoked only after a successful authentication session, for example by applying web‑application firewall rules or IP‑based access controls.
  • Ensure that the endpoint verifies primary credentials before validating the user UUID; enforce input validation so a UUID alone cannot grant access.

Generated by OpenCVE AI on August 2, 2026 at 08:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Three Learning
Three Learning koollab Lms
Weaknesses CWE-287
Vendors & Products Three Learning
Three Learning koollab Lms
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Description An authentication bypass vulnerability in Koollab LMS allowed an unauthenticated attacker to take over any account, including administrator accounts, by supplying a valid user UUID without providing primary credentials via the 2FA validation endpoint.
Title Authentication bypass vulnerability
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Three Learning Koollab Lms
cve-icon MITRE

Status: PUBLISHED

Assigner: CSA

Published:

Updated: 2026-07-29T14:28:37.043Z

Reserved: 2026-07-16T02:35:54.249Z

Link: CVE-2026-63238

cve-icon Vulnrichment

Updated: 2026-07-29T14:26:45.503Z

cve-icon NVD

Status : Deferred

Published: 2026-07-29T07:16:43.237

Modified: 2026-07-30T16:54:05.457

Link: CVE-2026-63238

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T08:30:12Z

Weaknesses