CVE-2026-63238

An authentication bypass vulnerability in Koollab LMS allowed an unauthenticated attacker to take over any account, including administrator accounts, by supplying a valid user UUID without providing primary credentials via the 2FA validation endpoint.
Configurations

No configuration.

History

29 Jul 2026, 15:16

Type Values Removed Values Added
CWE CWE-287

29 Jul 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-29 07:16

Updated : 2026-07-30 16:54


NVD link : CVE-2026-63238

Mitre link : CVE-2026-63238

CVE.ORG link : CVE-2026-63238


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication