Junglewise Threat Intelligence

CVE-2026-63233: Three Learning Koollab LMS SQL injection and RCE in assessment endpoint

CVE-2026-63233 · Severity: critical · CVSS 9.9 · Published 2026-07-29

Technologies: Three Learning Koollab LMS. Vendors: Three Learning.

Executive brief

Koollab LMS is a cloud-based learning management system used for e-learning and training administration. A critical vulnerability allows an authenticated user to execute malicious code on the server by exploiting the assessment answer system. This could lead to a complete takeover of the platform, unauthorized access to student data, and the ability to disrupt educational operations.

Technical details

The vulnerability exists in the 'assessment overall answer' endpoint of Koollab LMS. An authenticated attacker can perform a SQL injection to manipulate data that is subsequently passed to the PHP unserialize() function. By controlling the input to this function, an attacker can achieve remote code execution (RCE) through object injection. This allows the attacker to write a webshell to a publicly accessible directory on the server. The vendor has patched all cloud-hosted instances, and as a SaaS product, no user action is required.

Affected products

  • Three Learning Koollab LMS 5.3.2

Timeline

  • 2026-04-14: disclosed: Vendor disclosure
  • 2026-04-26: patched: Vendor patched cloud instances
  • 2026-07-29: advisory: Public release of advisory

References

Related threats