CVE-2026-63229
A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via
CVSS
9.1
Crítico
EPSS
0.3%
p22
KEV
—
Exploit Today
7
0-100
Publicado: 29 jul 2026 · Última mod.: 30 jul 2026 · CWE-89
0.3%EPSS · 30 días0.3%
2026-08-112026-09-07
A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via the SSO OAuth endpoint to read sensitive database contents, including personally identifiable information, credentials, and valid JWT tokens that may enable account takeover.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-697168.8 ALT—
———Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.6hCVE-2026-696366.5 MED—
———Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.6hCVE-2026-673708.8 ALT—
———Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.6hCVE-2026-668208.8 ALT—
———Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.6hCVE-2026-668198.8 ALT—
———Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.6hCVE-2026-628958.8 ALT—
———Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.6h