CVE-2026-56877
The SCORM lab launch endpoint in Skillable (scorm.skillable.com) through 2026-07-13 does not validate the client-supplied userId parameter against the authenticated SCORM session token. An authenticated user can substitute arbitrary userId values to bypass per-user lab launch rate limits and consume other users' lab allocations, resulting in denial of service against targeted users' lab and exam access. Skillable was formerly named Learn on Demand Systems.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- EPSS probability
- 0.39%
- CWE
- CWE-472
- Published
- 2026-07-13
- Last modified
- 2026-07-16
Affected products
- Skillable SCORM Lab Launch Integration
Weakness type
Related vulnerabilities
- CVE-2026-84762 — WordPress WP EasyPay plugin <= 4.5.3 - Bypass Vulnerability vulnerability
- CVE-2026-77999 — Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to order confirmation fraud in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6
- CVE-2026-67363 — Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2
- CVE-2026-1982 — Persian Elementor (المنتور فارسی) <= 2.8.1 - Unauthenticated Price Manipulation via ZarinPal Widget
- CVE-2026-7484 — Improper Access Control in Abis Technology's AVESİS
- CVE-2026-65052 — Ninja Forms Calculation and Payment Total Tampering via Fail-Open get_calc_value in ListSelect and ListRadio Fields
- CVE-2026-16089 — Keycloak-services: keycloak-services: authorization codes can be retargeted to another client session
- CVE-2026-59817 — Ghost: Paid gift memberships obtainable at minimal cost via the donations feature