CVE-2026-63240: Three Learning Koollab Lms

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

An information disclosure vulnerability in Koollab LMS allowed an authenticated learner to obtain correct quiz answers from the course status endpoint without completing the assessment legitimately, compromising the integrity of assessments.

Affected products

Published 2026-07-29. Last modified 2026-07-30.