Junglewise Threat Intelligence

CVE-2026-63231: Three Learning Koollab LMS SQL injection in face-to-face runs update endpoint

CVE-2026-63231 · Severity: high · CVSS 8.1 · Published 2026-07-29

Technologies: Three Learning Koollab LMS. Vendors: Three Learning.

Executive brief

Koollab LMS, a cloud-based learning management system used for corporate training and assessments, contains a security flaw in its face-to-face training update feature. An authorized user, such as a student or instructor, could exploit this flaw to access the entire underlying database. This could lead to the theft of sensitive personal information, login credentials, and security tokens, potentially allowing the attacker to take over other user accounts, including those of administrators.

Technical details

A post-authentication SQL injection vulnerability exists in Koollab LMS version 5.3.2 within the 'face-to-face runs update' endpoint. The flaw is rooted in insufficient sanitization of user-supplied input, allowing an authenticated attacker to perform error-based SQL injection. By leveraging an error-based SQL oracle, an attacker can exfiltrate sensitive data from the entire application database, including personally identifiable information (PII) and JSON Web Tokens (JWTs). These tokens can subsequently be used to facilitate account takeover. The vendor has patched all cloud-hosted (SaaS) instances, and no user action is required.

Affected products

  • Three Learning Koollab LMS 5.3.2

Timeline

  • 2026-04-14: disclosed: Vendor disclosure
  • 2026-04-26: patched: Vendor patched cloud instances
  • 2026-07-29: advisory: Public release of advisory

References

Related threats