Three Learning's Koollab LMS 5.3.2 was disclosed with multiple high-severity vulnerabilities that can expose databases, enable account takeover, and lead to remote code execution. The most critical issues include pre-authentication SQL injection in the SSO OAuth endpoint (CVE-2026-63229) and SCORM report endpoint (CVE-2026-63230), which allow unauthenticated attackers to read sensitive database contents such as personally identifiable information, credentials, and valid JWT tokens. A post-authentication SQL injection in the face-to-face runs update endpoint (CVE-2026-63231) can also expose the full application database and help attackers obtain JWTs for takeover of user accounts.
The advisory also details several paths to server-side code execution. An unrestricted SCORM upload flaw (CVE-2026-63227) lets an authenticated module designer place a PHP webshell in a publicly accessible directory, while two SQL injection and unsafe deserialization chains in the assessment reinforcement and manual mark assessment endpoints (CVE-2026-63232, CVE-2026-63234) allow authenticated attackers to influence data passed to unserialize(), write webshells, and execute arbitrary code on the server. Singapore's Cyber Security Agency said the broader disclosure covers 16 vulnerabilities across remote code execution, authentication bypass, access control, information disclosure, and business logic weaknesses, and that fixes were rolled out to all cloud-hosted SaaS instances by Three Learning.

See affected versions and whether adversaries are exploiting it.
9 events from the most recent confirmed update back to the earliest known activity.
A CVE record was published for a vulnerability in the manual mark assessment endpoint of Koollab LMS 5.3.2 that combines SQL injection and unsafe deserialization, enabling webshell upload and arbitrary code execution.
A CVE record was published for a vulnerability in the assessment reinforcement endpoint of Koollab LMS 5.3.2 that chains SQL injection with unsafe deserialization to write a webshell and execute code.
A CVE record was published for a post-authentication SQL injection flaw in the face-to-face runs update endpoint of Koollab LMS 5.3.2 that can expose the full application database and enable JWT theft for account takeover.
A CVE record was published for a pre-authentication error-based SQL injection vulnerability in the SCORM report endpoint of Koollab LMS 5.3.2, enabling unauthenticated access to sensitive database contents.
A CVE record was published for a pre-authentication blind SQL injection flaw in the SSO OAuth endpoint of Koollab LMS 5.3.2 that can expose sensitive database contents and valid JWT tokens.
A CVE record was published for an unrestricted SCORM file upload flaw in Koollab LMS 5.3.2 that allows an authenticated module designer to upload a PHP webshell and achieve arbitrary code execution.
On 2026-04-14, Singapore's Cyber Security Agency disclosed that Koollab LMS version 5.3.2 was affected by 16 vulnerabilities spanning remote code execution, SQL injection, authentication bypass, access control flaws, information disclosure, and business logic weaknesses.
The CSA advisory states the Koollab LMS vulnerability information was publicly released on 2026-07-29.
Three Learning stated that fixes for the disclosed Koollab LMS vulnerabilities were rolled out to all cloud-hosted SaaS instances on 2026-04-26.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
7 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecsa.gov.sg
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.