Description
A hard-coded AWS IAM credentials vulnerability
in Koollab LMS allowed
an attacker to access shared multi-tenant S3 buckets and SQS queues, exposing
sensitive data and enabling malicious content injection, job manipulation, or
email interception.
Published: 2026-07-29
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from hard‑coded AWS IAM credentials embedded in the Koollab LMS application. These credentials grant permissions to shared S3 buckets and SQS queues used by the multi‑tenant platform. An attacker who exploits this flaw can read or write to those buckets and queues, exposing sensitive data, injecting malicious content, manipulating queued jobs, or intercepting e‑mail streams. This flaw is classified as CWE‑798 – use of hard‑coded credentials.

Affected Systems

The affected vendor is Three Learning and the product is the Koollab LMS platform. The vulnerability applies to all deployments of this LMS that contain the hard‑coded credentials; no specific version numbers are in the advisory, so any installation prior to the vendor’s latest fix is potentially impacted.

Risk and Exploitability

The CVSS v3.1 score of 5.4 indicates a medium severity. The EPSS score of less than 1% suggests a low probability of exploitation under current conditions, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is exploitation of the web application through any user that can reach the LMS instance – the hard‑coded credentials are accessed by the application itself, so an attacker only needs network access to the LMS environment read or write the shared S3 buckets and SQS queues. No additional conditions are required beyond connectivity to the LMS instance.

Generated by OpenCVE AI on August 3, 2026 at 13:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Koollab LMS to the latest release that removes the hard‑coded AWS IAM credentials.
  • Restrict or disable public access to the shared S3 buckets and SQS queues that the LMS uses.
  • Rotate any AWS IAM credentials that may have been exposed and apply least‑privilege policies.
  • Contact Three Learning to confirm the availability of a vendor‑provided patch or to request a remediation timeline.

Generated by OpenCVE AI on August 3, 2026 at 13:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Three Learning
Three Learning koollab Lms
Weaknesses CWE-798
Vendors & Products Three Learning
Three Learning koollab Lms
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Description A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 buckets and SQS queues, exposing sensitive data and enabling malicious content injection, job manipulation, or email interception.
Title Hard-coded AWS IAM credentials vulnerability
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Three Learning Koollab Lms
cve-icon MITRE

Status: PUBLISHED

Assigner: CSA

Published:

Updated: 2026-07-29T14:24:06.894Z

Reserved: 2026-07-16T02:35:54.249Z

Link: CVE-2026-63239

cve-icon Vulnrichment

Updated: 2026-07-29T14:23:58.311Z

cve-icon NVD

Status : Deferred

Published: 2026-07-29T07:16:43.343

Modified: 2026-07-30T16:54:05.457

Link: CVE-2026-63239

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T14:00:07Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials