CVE Explorer
CVE-2026-56877
The SCORM lab launch endpoint in Skillable (scorm.skillable.com) through 2026-07-13 does not validate the client-supplied userId parameter against the authenticated SCORM session token. An authenticated user can substitute arbitrary userId values to bypass per-user lab launch rate limits and consume other users' lab allocations, resulting in denial of service against targeted users' lab and exam access. Skillable was formerly named Learn on Demand Systems.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unknown","product":"SCORM Lab Launch Integration","vendor":"Skillable","versions":[{"lessThanOrEqual":"2026-07-13","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:fdfca9219c74de56e8e00b2ce924d5e93ab78035cf7e8577cf883a269d53a2a3 · sha256:ba52955392d80c9a… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":6.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:fdfca9219c74de56e8e00b2ce924d5e93ab78035cf7e8577cf883a269d53a2a3 · sha256:ba52955392d80c9a… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-472","description":"CWE-472 External Control of Assumed-Immutable Web Parameter","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:fdfca9219c74de56e8e00b2ce924d5e93ab78035cf7e8577cf883a269d53a2a3 · sha256:ba52955392d80c9a… · /containers/cna/problemTypes/0/descriptions/0
Source references
5 source assertions{"url":"http://seclists.org/fulldisclosure/2026/Jul/20"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:fdfca9219c74de56e8e00b2ce924d5e93ab78035cf7e8577cf883a269d53a2a3 · sha256:ba52955392d80c9a… · /containers/adp/0/references/2
{"url":"http://www.openwall.com/lists/oss-security/2026/07/12/1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:fdfca9219c74de56e8e00b2ce924d5e93ab78035cf7e8577cf883a269d53a2a3 · sha256:ba52955392d80c9a… · /containers/adp/0/references/0
{"url":"http://www.openwall.com/lists/oss-security/2026/07/12/2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:fdfca9219c74de56e8e00b2ce924d5e93ab78035cf7e8577cf883a269d53a2a3 · sha256:ba52955392d80c9a… · /containers/adp/0/references/1
{"url":"https://www.openwall.com/lists/oss-security/2026/07/12/1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:fdfca9219c74de56e8e00b2ce924d5e93ab78035cf7e8577cf883a269d53a2a3 · sha256:ba52955392d80c9a… · /containers/cna/references/1
{"url":"https://www.skillable.com/security/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:fdfca9219c74de56e8e00b2ce924d5e93ab78035cf7e8577cf883a269d53a2a3 · sha256:ba52955392d80c9a… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.