CVE-2026-56877 - Skillable SCO... Note

CVE-2026-56877 - Skillable SCORM userId authorisation bypass

Posted by Greg via Fulldisclosure on Jul 15Skillable's SCORM lab launch endpoint validates a launch token but enforces per-user allocation limits using a browser-supplied userId that is not bound to the validated token. An authenticated learner can modify this identifier to bypass configured limits, launch concurrent lab instances, and consume another learner's allocation. Skillable states that no fix is planned for the legacy SCORM launch path. CVE-2026-56877 was assigned by...