Junglewise Threat Intelligence

CVE-2026-63241: Three Learning Koollab LMS IDOR in course completion query

CVE-2026-63241 · Severity: low · CVSS 3.1 · Published 2026-07-29

Technologies: Three Learning Koollab LMS. Vendors: Three Learning.

Executive brief

Koollab LMS is a cloud-based learning management system used for corporate training and e-learning. A security flaw allowed logged-in users to view the private course completion progress of any other student on the platform. While this does not allow for account takeover, it results in the unauthorized disclosure of private learning data.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in Koollab LMS version 5.3.2. The application fails to perform adequate authorization checks when a user queries course completion progress. An authenticated attacker can exploit this by manipulating object identifiers in network requests to retrieve the private learning progress and status of other users. The vendor has patched this vulnerability across all cloud-hosted SaaS instances; no user action is required.

Affected products

  • Three Learning Koollab LMS 5.3.2

Timeline

  • 2026-04-14: disclosed: Vendor disclosure
  • 2026-04-26: patched: Vendor patched cloud instances
  • 2026-07-29: advisory: Public release of advisory

References

Related threats