SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-63237

MEDIUM · CVSS 4.8 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

A vulnerability in Koollab LMS allows attackers to bypass two-factor authentication by supplying a client-controlled seed to generate a valid one-time password. This could lead to unauthorized access to administrator accounts, compromising the security of the system. Organizations using Koollab LMS should prioritize addressing this issue to protect sensitive administrative functions.

CVE
CVE-2026-63237
Severity
MEDIUM
CVSS
4.8
EPSS
0.12%

Original NVD Description

A TOTP two-factor authentication bypass vulnerability in Koollab LMS allowed an attacker to supply a client-controlled seed to generate a matching one-time password and bypass the second authentication factor, potentially enabling unauthorised access to administrator accounts.