CVE-2026-63241
Received
Received - Intake
Insecure Direct Object Reference in Koollab LMS Exposes User Progress Data
Vulnerability report for CVE-2026-63241, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-07-29
Last updated on: 2026-07-29
Assigner: CSA
Description
Description
An insecure direct object reference
vulnerability in Koollab LMS allowed an authenticated user to query the course completion progress
of any other user without authorisation, disclosing private learning progress
information.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |