An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to forcibly terminate the session of any user given their email address via the login kickout endpoint, resulting in a denial of service.
https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-094/