Skillable's hosted SCORM lab provisioning service was found vulnerable to CVE-2026-56877, a CWE-639 authorization flaw in which the browser-supplied userId parameter on GET /scorm/launch was not validated against the authenticated session token. An authenticated learner could alter that parameter to bypass per-user launch limits, start concurrent labs, and consume another learner's allocation, causing cross-user denial of service. The issue was confirmed against the reporter's own account and a consenting fellow student's account, and Skillable indicated the same weakness could also affect exam allocations and potentially expose another learner's active or saved session details.
Skillable said the affected path is part of its hosted platform and that no server-side fix is planned for the SCORM launch flow, instead recommending customers move to API-based or LTI 1.3 integrations. The vulnerability was assigned a CVSS 3.1 score of 6.5 and later drew discussion on the oss-security mailing list, where moderators noted the disclosure was off-topic because it involved a hosted service rather than open-source software; the thread also pointed to CVE Program guidance that cloud-service flaws may still receive CVEs when customer action is required.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
In a follow-up thread, an oss-security moderator said the Skillable issue was off-topic for the mailing list because it affected a hosted service rather than open source software. The same post noted MITRE had assigned a CVE and cited CVE Program guidance allowing cloud-service vulnerabilities to receive CVEs when customer action is required.
Skillable stated that no server-side fix was planned for the affected hosted SCORM launch flow and instead recommended customers migrate to API-based or LTI 1.3 integrations. The disclosure also noted the same weakness could affect exam allocations and potentially expose another learner's active or saved session details.
A vulnerability in Skillable's hosted SCORM lab provisioning service was disclosed in which the browser-supplied userId parameter was not validated against the SCORM launch token. The issue enabled launch-allocation bypass, concurrent lab launches, and cross-user denial of service, and was identified as CVE-2026-56877.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
7 references tracked. Mallory keeps watching after this page renders.
payloadforge.io
Open sourceseclists.org
Open sourcegithub.com
Open sourceseclists.org
Open sourceseclists.org
Open sourcecve.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.