SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-63242

MEDIUM · CVSS 4.3 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

A business logic vulnerability in Koollab LMS allows authenticated learners to falsely mark their lesson completion status as completed through the SCORM commit endpoint, bypassing the requirement to view the lesson material. This can compromise the integrity of training and completion records, potentially impacting educational outcomes and compliance. Organizations using Koollab LMS should prioritize addressing this vulnerability to maintain accurate training records and prevent misuse.

CVE
CVE-2026-63242
Severity
MEDIUM
CVSS
4.3
EPSS
0.15%

Original NVD Description

A business logic vulnerability in Koollab LMS allowed an authenticated learner to set their lesson completion status to completed via the SCORM commit endpoint without viewing the lesson material, compromising training and completion records.