CVE-2026-63236EPSS p16.5%
CVE-2026-63236CVE-2026-63236
Description
An improper access control vulnerability in
Koollab LMS allowed an
unauthenticated attacker to read another user's name, internal identifier,
scores, lesson status, lesson position, and cached lesson state via the SCORM
API endpoint.
Scoring
| CVSS | 3.7 () |
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
| EPSS | 0.26% probability of exploitation · percentile 16.5% · 2026-10-06T12:00:23Z |
| Last modified | 2026-07-30 |