CyberRota Analysis
AI-GeneratedAn improper access control vulnerability in Koollab LMS allows unauthenticated attackers to terminate the sessions of users by exploiting the login kickout endpoint with their email addresses. This can lead to a denial of service, disrupting user access to the platform. Organizations using Koollab LMS should prioritize addressing this issue to prevent potential service interruptions.
CVE
CVE-2026-63235
Severity
LOW
CVSS
3.7
EPSS
0.20%
Original NVD Description
An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to forcibly terminate the session of any user given their email address via the login kickout endpoint, resulting in a denial of service.