CVE-2026-63240
Received
Received - Intake
Authenticated Information Disclosure in Koollab LMS via Quiz Answers Exposure
Vulnerability report for CVE-2026-63240, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-07-29
Last updated on: 2026-07-29
Assigner: CSA
Description
Description
An information disclosure vulnerability in Koollab LMS allowed an authenticated learner
to obtain correct quiz answers from the course status endpoint without
completing the assessment legitimately, compromising the integrity of
assessments.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| koollab | lms | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |