Junglewise Threat Intelligence

CVE-2026-63235: Three Learning Koollab LMS improper access control in login kickout endpoint

CVE-2026-63235 · Severity: low · CVSS 3.7 · Published 2026-07-29

Technologies: Three Learning Koollab LMS. Vendors: Three Learning.

Executive brief

Koollab LMS, a cloud-based learning management system used for corporate training and assessments, contains a security flaw in its login management component. An unauthorized individual could exploit this to remotely log out any active user if they know that user's email address. This results in a targeted denial of service, disrupting the learning or testing experience for students and staff.

Technical details

An improper access control vulnerability exists within the 'login kickout' endpoint of Koollab LMS version 5.3.2. The endpoint fails to adequately verify the authorization of the requester before processing a session termination command. An unauthenticated remote attacker can exploit this by sending a crafted request containing a target user's email address to the vulnerable endpoint. Successful exploitation results in the immediate termination of the target user's active session, leading to a localized denial of service. The vendor has patched this vulnerability across its SaaS infrastructure.

Affected products

  • Three Learning Koollab LMS 5.3.2

Timeline

  • 2026-04-14: disclosed: Vendor disclosure
  • 2026-04-26: patched: Vendor patched cloud-hosted instances
  • 2026-07-29: advisory: Public release of advisory

References

Related threats