CVE-2026-63229
A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via
CVSS
9.1
Critical
EPSS
0.3%
p22
KEV
—
Exploit Today
7
0-100
Published: Jul 29, 2026 · Last modified: Jul 30, 2026 · CWE-89
0.3%EPSS · 30 days0.3%
2026-08-112026-09-07
A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via the SSO OAuth endpoint to read sensitive database contents, including personally identifiable information, credentials, and valid JWT tokens that may enable account takeover.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-697168.8 HIG—
———Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.6hCVE-2026-696366.5 MED—
———Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.6hCVE-2026-673708.8 HIG—
———Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.6hCVE-2026-668208.8 HIG—
———Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.6hCVE-2026-668198.8 HIG—
———Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.6hCVE-2026-628958.8 HIG—
———Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.6h