CVE-2026-63240

MEDIUM

Three Learning Koollab Lms < 5.3.2 - Information Disclosure

Title source: rule
STIX 2.1

Description

An information disclosure vulnerability in Koollab LMS allowed an authenticated learner to obtain correct quiz answers from the course status endpoint without completing the assessment legitimately, compromising the integrity of assessments.

Scores

CVSS v3 4.3
EPSS 0.0018
EPSS Percentile 7.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
Three Learning/Koollab LMS 5.3.2
Published Jul 29, 2026
Tracked Since Jul 29, 2026