Executive brief
Koollab LMS is a cloud-based platform used for corporate training and e-learning. A security flaw involving hard-coded Amazon Web Services (AWS) credentials allowed unauthorized access to the platform's shared storage and messaging systems. This could have resulted in the exposure of sensitive student data, the injection of malicious content into courses, or the interception of system emails.
Technical details
The vulnerability stems from the inclusion of hard-coded AWS IAM credentials within the Koollab LMS application. An attacker with network access could extract these credentials to gain unauthorized access to the provider's multi-tenant AWS infrastructure, specifically S3 buckets and SQS queues. This access allows for the exfiltration of sensitive data, modification of stored content (content injection), and manipulation of background jobs or email communications. The vendor, Three Learning, has patched this vulnerability across its SaaS infrastructure; since it is a cloud-hosted service, no user action is required.
Affected products
- Three Learning Koollab LMS 5.3.2
Timeline
- 2026-04-14: disclosed: Vendor disclosure
- 2026-04-26: patched: Vendor patched cloud instances
- 2026-07-29: advisory: Public release of advisory