Koollab LMS: 14 Vulnerabilities Disclosed, Featuring Critical SQL Injection and Code Execution Flaws
Koollab LMS hit with 14 vulnerabilities on July 29, 2026, including critical flaws enabling code execution and data theft.

Key findings
- 14 vulnerabilities disclosed for Koollab LMS on July 29, 2026, including critical SQL injection and unsafe deserialization flaws.
- Critical vulnerabilities allow arbitrary code execution and sensitive data exfiltration, including PII and JWT tokens.
- Multiple access control issues enable unauthorized data viewing, session termination, and false lesson completion.
- Hard-coded AWS IAM credentials and unrestricted file uploads pose significant risks to multi-tenant environments.
- Urgent patching is required to address severe security weaknesses in Koollab LMS.
On July 29, 2026, a significant batch of 14 vulnerabilities was disclosed for Koollab's Learning Management System (LMS), with a critical cluster of high and critical severity flaws posing a severe risk to data integrity and system security. The vulnerabilities, all disclosed on the same day, highlight a range of security weaknesses including SQL injection, unsafe deserialization, and improper access controls.
Several critical vulnerabilities center around SQL injection and unsafe deserialization, allowing authenticated attackers to execute arbitrary code on the server. CVE-2026-63234, CVE-2026-63233, and CVE-2026-63232 all share this dangerous combination, enabling attackers to write webshells to publicly accessible locations. Additionally, CVE-2026-63227, a critical unrestricted SCORM file upload vulnerability, allows authenticated module designers to upload SCORM packages containing webshells, leading to arbitrary code execution.
Further compounding the risk, CVE-2026-63231, a high-severity post-authentication SQL injection, allows attackers to extract the entire application database and obtain valid JWT tokens for account takeover. A pre-authentication blind SQL injection, CVE-2026-63229 (critical severity), also enables attackers to exfiltrate sensitive database contents, including PII and credentials, via a time-based SQL oracle on the SSO OAuth endpoint.
Other vulnerabilities include a business logic flaw (CVE-2026-63242, Medium) allowing learners to falsely mark lessons as complete, and an insecure direct object reference (CVE-2026-63241, Low) that exposes other users' course progress. An information disclosure vulnerability (CVE-2026-63240, Medium) allows learners to obtain quiz answers without legitimate completion. A hard-coded AWS IAM credentials vulnerability (CVE-2026-63239, Medium) could lead to sensitive data exposure and malicious content injection. A TOTP two-factor authentication bypass (CVE-2026-63235, Medium) could allow unauthorized access to administrator accounts.
Improper access control vulnerabilities (CVE-2026-63236, Low and CVE-2026-63235, Low) allow unauthenticated attackers to read user data or terminate user sessions, respectively. Finally, an unrestricted image upload vulnerability (CVE-2026-63228, Low) could enable further attacks on the server.
The coordinated disclosure of these 14 vulnerabilities on July 29, 2026, underscores the urgent need for Koollab LMS users to apply available patches and review their security configurations. The presence of multiple critical vulnerabilities, particularly those allowing arbitrary code execution and sensitive data exfiltration, necessitates immediate attention to mitigate the risk of system compromise and data breaches. Users should prioritize updating to patched versions as soon as possible to protect their training records and sensitive information.
The full list of affected CVEs includes CVE-2026-63242, CVE-2026-63241, CVE-2026-63240, CVE-2026-63239, CVE-2026-63237, CVE-2026-63236, CVE-2026-63235, CVE-2026-63234, CVE-2026-63233, CVE-2026-63232, CVE-2026-63231, CVE-2026-63229, CVE-2026-63228, and CVE-2026-63227. It is recommended that administrators consult Koollab's official security advisories for specific patching instructions and affected version details. Given the severity of the vulnerabilities, a prompt response is crucial to safeguard the integrity of training data and user credentials.