CVE-2026-63242
Received
Received - Intake
Business Logic Flaw in Koollab LMS Allows Fake Lesson Completion
Vulnerability report for CVE-2026-63242, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-07-29
Last updated on: 2026-07-29
Assigner: CSA
Description
Description
A business logic vulnerability in Koollab LMS
allowed an
authenticated learner to set their lesson completion status to completed via
the SCORM commit endpoint without viewing the lesson material, compromising
training and completion records.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| koollab | lms | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |