CVE-2026-63227: Critical RCE Vulnerability in Koollab LMS (CVSS 9.9)
This text was generated using artificial intelligence (AI).On July 29, 2026, the Cyber Security Agency of Singapore (CSA) disclosed a critical vulnerability in the Koollab learning management system (LMS) from the vendor Three Learning. The vulnerability, identified as CVE-2026-63227 According to CSA Advisory AL-2026-094, this vulnerability has a CVSS score of 9.9 (Critical) is exploited, allowing attackers to take complete control of the affected server through remote code execution (RCE).
The affected version is 5.3.2 the software. A security update to version 5.4.0, which addresses the issue, was provided by the manufacturer.
The cause of CVE-2026-63227 is insufficient validation of uploaded SCORM packages. SCORM (Sharable Content Object Reference Model) is a standard for e-learning content that is often provided in the form of ZIP archives. The vulnerable function allows an authenticated user with the role of a module designer to upload a manipulated SCORM package that contains a PHP webshell.
Since the application does not check the contents of the archive, the webshell is extracted into a publicly accessible directory on the server. The attacker can then access the webshell directly via a URL and execute arbitrary commands on the server's operating system.
According to the CSA, the CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H and confirms its high criticality. One crucial detail, however, is the component Privileges Required: Low (PR:L). This means that an attacker must already have a valid, low-privileged account to exploit the vulnerability. The risk therefore stems primarily from compromised user accounts or malicious insiders. At the time of disclosure, no active exploitation was known, according to the CSA.
Business Impact and Risk Assessment
A successful exploit of the RCE vulnerability has serious consequences. Attackers gain complete control over the LMS server and can:
Exfiltrating confidential data: Personal data of employees or course participants, internal course materials, and other sensitive information could be stolen.
Manipulating systems: Data can be altered or deleted, ransomware can be executed, or the server can be misused for further attacks.
Hacking into the internal network: The compromised server can serve as a foothold for attacks on other systems within the corporate network.
Companies that use Koollab LMS are at high risk, especially if the management of user accounts for course designers is not strictly controlled.
For organizations based in the EU or the DACH region, the following applies: If a successful exploit affects the personal data of students or employees, there is an obligation under Article 33 of the GDPR to notify the relevant supervisory authority within 72 hours. Companies in NIS 2-regulated sectors—such as critical educational institutions or digital service providers—should also take this vulnerability into account as part of their risk assessment and incident management process.
As early as April 2026, CSA Singapore had disclosed a stored XSS vulnerability in the same platform (CVE-2026-3007, AL-2026-042). The repeated occurrence of serious security vulnerabilities in the same product within a few months underscores the importance of ongoing vendor risk management with regard to third-party software providers.
Recommended Actions
Organizations using Koollab LMS version 5.3.2 should take immediate action. Full technical details and recommended actions are provided in the CSA Advisory AL-2026-094 available.
Identification and Patching (Immediate): Identify all instances of Koollab LMS in your infrastructure. Affected systems must be prioritized and updated to the secure version immediately 5.4.0 be updated.
Compromise Assessment (Short-Term): Check the upload directories for SCORM content for suspicious files, particularly PHP scripts or other unexpected file types. Such findings indicate that the system has already been compromised.
Risk Management (Strategic): Establish processes for continuous vulnerability and supplier risk management to systematically monitor and assess risks associated with third-party software.
How LocateRisk Helps Minimize Risk
Vulnerabilities in purchased software are a key component of third-party and vendor risk management. The LocateRisk platform helps companies manage these risks.
External Attack Surface Management (EASM): LocateRisk identifies all externally accessible systems and applications running under a company’s domains. This includes instances of Koollab LMS that may exist as shadow IT without the IT department’s knowledge. This visibility is essential for quickly identifying and patching affected systems.
Vendor Risk Management (VRM): The platform continuously assesses the security of third-party providers and their products. By monitoring the digital supply chain, risks posed by software such as Koollab LMS can be identified early on and incorporated into the company’s risk assessment. The Koollab LMS case serves as a prime example of how a vendor with repeated vulnerabilities can increase an organization’s overall risk—a pattern that LocateRisk brings to light as part of its continuous vendor monitoring.
CVE-2026-63227 is a vulnerability in Koollab LMS (version 5.3.2), which allows an authenticated user with the role of a module designer to upload a manipulated SCORM package that places a PHP webshell in a publicly accessible directory. Through this webshell, the attacker can execute arbitrary commands on the server. The CVSS score of 9.9 (Critical) reflects the extreme potential for damage resulting from a successful exploit.
Only Koollab LMS version 5.3.2 is affected. Three Learning has released a security update to version 5.4.0 that addresses the vulnerability. Administrators should install the update immediately and then check the SCORM upload directories for any existing PHP scripts.
As of the disclosure date of July 29, 2026, CSA Singapore reported that no active exploitation was known. However, given the high CVSS score and the public availability of the vulnerability information, a prompt update to version 5.4.0 is strongly recommended.
As of July 29, 2026. This article is intended for general informational purposes only and does not constitute legal, security, or operational advice in specific cases. The security situation and patch availability may have changed since publication; the linked vendor advisory is always authoritative. Despite careful research, we do not guarantee that the information is up-to-date, accurate, or complete.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2024-3094
Passive Assessment
Information About the CVENotes found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.