THREAT OPS › Threat News › CVE-2026-56877 - Skillable SCORM userId authorisation bypass
CVE-2026-56877 - Skillable SCORM userId authorisation bypass
<p>Posted by Greg via Fulldisclosure on Jul 15</p>Skillable's SCORM lab launch endpoint validates a launch token but<br /> enforces per-user allocation limits using a browser-supplied userId<br /> that is not bound to the validated token. An authenticated learner<br /> can modify this identifier to bypass configured limits, launch<br /> concurrent lab instances, and consume another learner&ap
Indicators of compromise
- CVE-2026-56877cve
Original source: https://seclists.org/fulldisclosure/2026/Jul/20