Executive brief
Koollab LMS is a cloud-based learning management system used for corporate training and e-learning. A security flaw allowed logged-in users to view the private course completion progress of any other student on the platform. While this does not allow for account takeover, it results in the unauthorized disclosure of private learning data.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in Koollab LMS version 5.3.2. The application fails to perform adequate authorization checks when a user queries course completion progress. An authenticated attacker can exploit this by manipulating object identifiers in network requests to retrieve the private learning progress and status of other users. The vendor has patched this vulnerability across all cloud-hosted SaaS instances; no user action is required.
Affected products
- Three Learning Koollab LMS 5.3.2
Timeline
- 2026-04-14: disclosed: Vendor disclosure
- 2026-04-26: patched: Vendor patched cloud instances
- 2026-07-29: advisory: Public release of advisory