Junglewise Threat Intelligence

CVE-2026-63236: Three Learning Koollab LMS improper access control in SCORM API

CVE-2026-63236 · Severity: low · CVSS 3.7 · Published 2026-07-29

Technologies: Three Learning Koollab LMS. Vendors: Three Learning.

Executive brief

Koollab LMS, a cloud-based learning management system, was found to have a security flaw in its SCORM API. This vulnerability allowed unauthorized individuals to view sensitive student information, including names, internal IDs, and detailed lesson progress or scores. The vendor has already applied a fix to all cloud-hosted instances, so no customer action is required.

Technical details

An improper access control vulnerability exists within the SCORM API endpoint of Koollab LMS version 5.3.2. The flaw allows an unauthenticated remote attacker to bypass authorization checks and retrieve sensitive learner data belonging to other users. Exposed data includes user names, internal identifiers, assessment scores, lesson status, and cached lesson states. The vulnerability was addressed by the vendor, Three Learning, across all cloud-hosted SaaS instances in April 2026. An attacker would likely need to guess or obtain specific identifiers to target individual records, contributing to the 'High' attack complexity rating.

Affected products

  • Three Learning Koollab LMS 5.3.2

Timeline

  • 2026-04-14: disclosed: Vendor disclosure
  • 2026-04-26: patched: Vendor patched cloud instances
  • 2026-07-29: advisory: Public release of advisory

References

Related threats