Security Advisory

CVE-2026-63239

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-29 06:28:44
Last updated 2026-07-29 14:24:06
Assigner CSA
CVSS score not scored
State PUBLISHED

Description

A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 buckets and SQS queues, exposing sensitive data and enabling malicious content injection, job manipulation, or email interception.