Junglewise Threat Intelligence

CVE-2026-63234: Three Learning Koollab LMS SQL injection and unsafe deserialization

CVE-2026-63234 · Severity: critical · CVSS 9.9 · Published 2026-07-29

Technologies: Three Learning Koollab LMS. Vendors: Three Learning.

Executive brief

Koollab LMS, a cloud-based learning management system used for corporate training and assessments, contains a critical security flaw. An authorized user, such as a student or instructor, can exploit the manual marking feature to gain full control over the server. This could lead to the theft of sensitive student data, modification of training records, or a complete shutdown of the learning platform.

Technical details

A critical vulnerability exists in Koollab LMS version 5.3.2 within the manual mark assessment endpoint. The flaw combines SQL injection with unsafe deserialization, where an authenticated attacker can inject malicious payloads to control data passed to the PHP unserialize() function. By leveraging this, an attacker can achieve remote code execution (RCE) and write a webshell to a publicly accessible directory on the server. The vendor, Three Learning, has patched all cloud-hosted instances of this SaaS product, so no manual user action is required.

Affected products

  • Three Learning Koollab LMS 5.3.2

Timeline

  • 2026-04-14: disclosed: Disclosed to vendor
  • 2026-04-26: patched: Vendor patched cloud instances
  • 2026-07-29: advisory: Public release of advisory

References

Related threats