Junglewise Threat Intelligence

CVE-2026-63229: Three Learning Koollab LMS blind SQL injection in SSO OAuth endpoint

CVE-2026-63229 · Severity: critical · CVSS 9.1 · Published 2026-07-29

Technologies: Three Learning Koollab LMS. Vendors: Three Learning.

Executive brief

Koollab LMS is a cloud-based platform used for corporate training and e-learning. A security flaw in its login system allows unauthorized attackers to extract sensitive information from the database without needing a password. This could lead to the theft of personal user data, login credentials, and security tokens, potentially allowing attackers to take over user accounts.

Technical details

A blind, time-based SQL injection vulnerability exists in the SSO OAuth endpoint of Koollab LMS version 5.3.2. An unauthenticated remote attacker can send specially crafted requests to the endpoint and use a time-based SQL oracle to exfiltrate data from the backend database. Successful exploitation allows for the retrieval of personally identifiable information (PII), user credentials, and valid JSON Web Tokens (JWTs), which can be leveraged for full account takeover. The vendor has patched this vulnerability in their SaaS environment; no user action is required for cloud-hosted instances.

Affected products

  • Three Learning Koollab LMS 5.3.2

Timeline

  • 2026-04-14: disclosed: Vulnerability reported to vendor
  • 2026-04-26: patched: Vendor rolled out fixes to cloud-hosted instances
  • 2026-07-29: advisory: Public release of advisory by CSA Singapore and NVD publication

References

Related threats