CVE-2026-63236
An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to read another user's name, internal identifier
CVSS
3.7
Low
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Jul 29, 2026 · Last modified: Jul 29, 2026 · CWE-284
Not enough EPSS history yet.
An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to read another user's name, internal identifier, scores, lesson status, lesson position, and cached lesson state via the SCORM API endpoint.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-65888——
———Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.8hCVE-2026-65887——
———Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super admins.8hCVE-2026-65889——
———Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories.8hCVE-2026-659437.5 HIG—
———Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.07hCVE-2026-65884——
———Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissions.8hCVE-2026-419209.3 CRI—
——0Improper Access Control vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.1.15 or 10.1.4, which fixes the issue.9h