Junglewise Threat Intelligence

CVE-2026-63240: Three Learning Koollab LMS information disclosure in course status endpoint

CVE-2026-63240 · Severity: medium · CVSS 4.3 · Published 2026-07-29

Technologies: Three Learning Koollab LMS. Vendors: Three Learning.

Executive brief

Koollab LMS is a cloud-based platform used for corporate training and educational assessments. A security flaw allowed students to view the correct answers to quiz questions through a specific system endpoint without actually completing the test. This undermines the integrity of the training program and allows users to bypass legitimate assessment requirements.

Technical details

An information disclosure vulnerability exists in the course status endpoint of Koollab LMS version 5.3.2. The root cause is improper access control or data filtering on the course status API, which returns sensitive quiz metadata to the client. An authenticated attacker with 'learner' privileges can query this endpoint to retrieve correct answers for assessments they have not yet completed. This allows for the bypass of assessment integrity controls. The vendor, Three Learning, has patched this vulnerability across all cloud-hosted SaaS instances; no user action is required.

Affected products

  • Three Learning Koollab LMS 5.3.2

Timeline

  • 2026-04-14: disclosed: Vendor disclosure
  • 2026-04-26: patched: Vendor patched cloud instances
  • 2026-07-29: advisory: Public release of advisory

References

Related threats