Back to overview

CVE-2026-63239

MEDIUM
5.4
CVSS 3.1
Description
A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 buckets and SQS queues, exposing sensitive data and enabling malicious content injection, job manipulation, or email interception.

Metadata

CVE ID
CVE-2026-63239
State
PUBLISHED
Assigner
CSA
Reserved
2026-07-16 02:35 UTC
Published
2026-07-29 06:28 UTC
Last updated
2026-07-29 06:28 UTC
Vendor / Product
Three Learning / Koollab LMS
Sources
cve.org  ·  NVD

Severity & Metrics

5.4 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected products (1)
VendorProductPlatformVersions
Three Learning Koollab LMS 5.3.2
CVSS scores (1)
ScoreSeverityVersionSourceVector
5.4 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Back to overview