SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-63239

MEDIUM · CVSS 5.4 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

A hard-coded AWS IAM credentials vulnerability in Koollab LMS allows attackers to gain unauthorized access to shared multi-tenant S3 buckets and SQS queues, potentially exposing sensitive data and enabling malicious activities such as content injection, job manipulation, or email interception. Organizations using Koollab LMS should prioritize remediation efforts to mitigate the risk of data breaches and protect user information.

CVE
CVE-2026-63239
Severity
MEDIUM
CVSS
5.4
EPSS
0.12%

Original NVD Description

A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 buckets and SQS queues, exposing sensitive data and enabling malicious content injection, job manipulation, or email interception.