CVE-2026-63235
LOW
NVD
CVSS Score
3.7
Severity
LOW
Published
Jul 29, 2026
Vendor
unknown
Description
An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to forcibly terminate the session of any user given their email address via the login kickout endpoint, resulting in a denial of service.