SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-63241

LOW · CVSS 3.1 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

An insecure direct object reference vulnerability in Koollab LMS enables authenticated users to access and query the course completion progress of other users without proper authorization, leading to unauthorized disclosure of private learning progress data. Organizations using Koollab LMS should prioritize addressing this issue to protect user privacy and maintain compliance with data protection regulations. Although classified as low severity, the potential for privacy breaches warrants attention, especially in educational environments.

CVE
CVE-2026-63241
Severity
LOW
CVSS
3.1
EPSS
0.14%

Original NVD Description

An insecure direct object reference vulnerability in Koollab LMS allowed an authenticated user to query the course completion progress of any other user without authorisation, disclosing private learning progress information.