« Volver al listado

CVE-2026-63237

Estado: AplazadaMedia (4.8)—

A TOTP two-factor authentication bypass vulnerability in Koollab LMS allowed an attacker to supply a client-controlled seed to generate a matching one-time password and bypass the second authentication factor, potentially enabling unauthorised access to administrator accounts.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-63237",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-63237",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-07-29T14:29:10.771467Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.8,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4",
      "affectedData": [
        {
          "vendor": "Three Learning",
          "product": "Koollab LMS",
          "versions": [
            {
              "status": "affected",
              "version": "5.3.2"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-07-29T07:16:43.133",
  "references": [
    {
      "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-094/",
      "source": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-347"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A TOTP two-factor authentication bypass vulnerability in\nKoollab LMS allowed an\nattacker to supply a client-controlled seed to generate a matching one-time\npassword and bypass the second authentication factor, potentially enabling\nunauthorised access to administrator accounts."
    }
  ],
  "lastModified": "2026-07-30T16:54:05.457",
  "sourceIdentifier": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4"
}