Junglewise Threat Intelligence

CVE-2026-63238: Three Learning Koollab LMS authentication bypass in 2FA endpoint

CVE-2026-63238 · Severity: medium · CVSS 6.5 · Published 2026-07-29

Technologies: Three Learning Koollab LMS. Vendors: Three Learning.

Executive brief

Koollab LMS, a cloud-based learning management system used for corporate training and assessments, contained a flaw that could allow unauthorized individuals to take over any user account. By exploiting a weakness in the two-factor authentication (2FA) process, an attacker could gain full access to student or administrator accounts without knowing their passwords. The vendor has already applied a fix to all cloud-hosted instances, so no action is required by customers.

Technical details

An authentication bypass vulnerability exists in the 2FA validation endpoint of Koollab LMS version 5.3.2. The flaw allows an unauthenticated attacker to bypass the primary credential requirement by directly interacting with the two-factor authentication (2FA) validation component. By providing a valid target user's UUID to this endpoint, an attacker can gain full session access to that account, including administrative accounts, without ever providing a password. The vendor, Three Learning, has patched this vulnerability across all cloud-hosted SaaS instances as of April 2026.

Affected products

  • Three Learning Koollab LMS 5.3.2

Timeline

  • 2026-04-14: disclosed: Vulnerability disclosed to vendor
  • 2026-04-26: patched: Vendor rolled out fixes to cloud instances
  • 2026-07-29: advisory: Public advisory released by CSA Singapore and NVD

References

Related threats