Junglewise Threat Intelligence

CVE-2026-63237: Three Learning Koollab LMS TOTP 2FA bypass

CVE-2026-63237 · Severity: medium · CVSS 4.8 · Published 2026-07-29

Technologies: Three Learning Koollab LMS. Vendors: Three Learning.

Executive brief

Koollab LMS, a cloud-based learning management system, was found to have a security flaw in its two-factor authentication (2FA) process. An attacker could potentially bypass the secondary security layer by providing their own security 'seed' to generate a valid login code. If successful, this could allow unauthorized access to user accounts, including those with administrative privileges, compromising sensitive training data and system settings.

Technical details

A vulnerability in the Time-based One-Time Password (TOTP) implementation of Koollab LMS allowed for a 2FA bypass. The flaw stems from the application permitting a client-controlled seed to be supplied during the authentication process. By providing a known seed, an attacker can generate the corresponding valid TOTP token, effectively neutralizing the second factor of authentication. This could lead to unauthorized access to administrator accounts if the primary credentials are also compromised or bypassed. The vendor has patched this vulnerability across its SaaS infrastructure.

Affected products

  • Three Learning Koollab LMS 5.3.2

Timeline

  • 2026-04-14: disclosed: Vendor disclosure
  • 2026-04-26: patched: Vendor rolled out fixes to cloud-hosted instances
  • 2026-07-29: advisory: Public release of advisory

References

Related threats