Full Disclosure mailing list archives
CVE-2026-56877 - Skillable SCORM userId authorisation bypass
From: Greg via Fulldisclosure
Date: Sun, 12 Jul 2026 10:19:54 +0000
Skillable's SCORM lab launch endpoint validates a launch token but enforces per-user allocation limits using a browser-supplied userId that is not bound to the validated token. An authenticated learner can modify this identifier to ...
