in Koollab LMS allowed
an attacker to access shared multi-tenant S3 buckets and SQS queues, exposing
sensitive data and enabling malicious content injection, job manipulation, or
email interception.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 29 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Three Learning
Three Learning koollab Lms |
|
| Weaknesses | CWE-798 | |
| Vendors & Products |
Three Learning
Three Learning koollab Lms |
|
| Metrics |
ssvc
|
Wed, 29 Jul 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 buckets and SQS queues, exposing sensitive data and enabling malicious content injection, job manipulation, or email interception. | |
| Title | Hard-coded AWS IAM credentials vulnerability | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CSA
Published:
Updated: 2026-07-29T14:24:06.894Z
Reserved: 2026-07-16T02:35:54.249Z
Link: CVE-2026-63239
Updated: 2026-07-29T14:23:58.311Z
Status : Deferred
Published: 2026-07-29T07:16:43.343
Modified: 2026-07-30T16:54:05.457
Link: CVE-2026-63239
No data.
OpenCVE Enrichment
Updated: 2026-08-03T14:00:07Z