Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-63230 -- CVSS 9.1 Vulnerability Briefing

CVE-2026-63230 | CVSS 9.1 (Critical) | Exploit: PoC available

What Is It

CVE-2026-63230 is a critical pre-authentication error-based SQL injection vulnerability in the Koollab LMS SCORM report endpoint.

Technical Detail

The affected endpoint insufficiently handles attacker-controlled input used in database queries, allowing unauthenticated SQL injection through error-based techniques. An attacker may be able to extract sensitive database contents without valid credentials, including personally identifiable information, stored credentials, and valid JWT tokens. Compromised JWT tokens may permit account takeover, depending on token validity, signing configuration, and the privileges associated with affected accounts.

Exploitation Status

A proof of concept is available. CISA has not listed this vulnerability in the Known Exploited Vulnerabilities catalog, and active exploitation in the wild is not confirmed by the available data.

Who Is Targeting This

No specific threat actor attribution at this time.

What To Do

Prioritize applying the vendor-provided security update or remediation for Koollab LMS immediately, particularly for internet-accessible deployments. If an update is not available, restrict access to the SCORM report endpoint to trusted administrative networks or authenticated reverse-proxy controls, and consider temporarily disabling the endpoint where operationally feasible. Review web and application logs for anomalous requests to SCORM reporting functionality, database error responses, repeated malformed parameters, and unusually large or unexpected report-query activity. Assume exposed JWT tokens and credentials may be compromised: rotate application secrets and database credentials, invalidate and reissue active JWT sessions where supported, and investigate potentially affected accounts and database-access logs.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →