<p>Posted by Greg via Fulldisclosure on Jul 15</p>Skillable&apos;s SCORM lab launch endpoint validates a launch token but<br> enforces per-user allocation limits using a browser-supplied userId<…
| CVE ID | CVE-2026-56877 |
| Vendor | SecLists |
| Affected Product | Multiple Targets |
| Vulnerability Type | Zero-Day Exploit |
| CVSS Score | 8.0 (HIGH) |
| Actively Exploited | ❌ No known exploitation |
| Patch Status | See Vendor Advisory → |
| Reported By | CYBERDUDEBIVASH SENTINEL APEX Intelligence (via fulldisclosure) |
<p>Posted by Greg via Fulldisclosure on Jul 15</p>Skillable&apos;s SCORM lab launch endpoint validates a launch token but<br> enforces per-user allocation limits using a browser-supplied userId<br> that is not bound to the validated token. An authenticated learner<br> can modify this identifier to bypass configured limits, launch<br> concurrent lab instances, and consume another learner&apos;s allocation.<br> Skillable states that no fix is planned for the legacy SCORM launch<br> path. CVE-2026-56877 was assigned by...<br>
Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.