CVE-2026-63239
MEDIUM
NVD
CVSS Score
5.4
Severity
MEDIUM
Published
Jul 29, 2026
Vendor
unknown
Description
A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 buckets and SQS queues, exposing sensitive data and enabling malicious content injection, job manipulation, or email interception.