THREATOPS
THREAT OPSThreat News › CVE-2026-56877 - Skillable SCORM userId authorisation bypass

CVE-2026-56877 - Skillable SCORM userId authorisation bypass

lowfulldisclosurePublished 2026-07-16

<p>Posted by Greg via Fulldisclosure on Jul 15</p>Skillable&apos;s SCORM lab launch endpoint validates a launch token but<br /> enforces per-user allocation limits using a browser-supplied userId<br /> that is not bound to the validated token. An authenticated learner<br /> can modify this identifier to bypass configured limits, launch<br /> concurrent lab instances, and consume another learner&ap

Indicators of compromise

Original source: https://seclists.org/fulldisclosure/2026/Jul/20