CVE-2026-63236

LOW

Three Learning Koollab LMS 5.3.2 - Unauthenticated SCORM Data Exposure

Title source: manual
STIX 2.1

Description

An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to read another user's name, internal identifier, scores, lesson status, lesson position, and cached lesson state via the SCORM API endpoint.

Scores

CVSS v3 3.7
EPSS 0.0017
EPSS Percentile 6.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (1)
Three Learning/Koollab LMS 5.3.2
Published Jul 29, 2026
Tracked Since Jul 29, 2026