HomeSecurityKnowledgeDeliver LMS: Vulnerability allows RCE attacks

KnowledgeDeliver LMS: Vulnerability allows RCE attacks

A particularly serious cybersecurity incident has brought new risks to light, after it was revealed that Digital Knowledge KnowledgeDeliver, one of the most widely used Learning Management Systems (LMS) in Japan, was used as an entry point for targeted cyberattacks. The vulnerability, which has now been patched, was exploited by unknown attackers as a zero-day exploit to install the Godzilla web shell and then deploy the Cobalt Strike Beacon.

KnowledgeDeliver

The vulnerability was reported as CVE-2026-5426 and received a CVSS score of 7.5, which classifies it as a dangerous remote code execution. According to security researchers from Google Mandiant and the Google Threat Intelligence Group, the issue stemmed from the use of ASP.NET machine keys with hardcoded settings, which allowed for deserialization attacks via the ViewState mechanism.

See also: Godzilla Fileless Backdoor exploits Atlassian Confluence vulnerability

How Attackers Exploited ASP.NET ViewState

ViewState technology in ASP.NET is used to persist data and state of a web page between different user requests. However, when the machine keys used to sign and encrypt this data are known or shared, it creates an extremely dangerous security scenario.

In the case of KnowledgeDeliver, installations relied on a default web.config file provided by the platform manufacturer. This file contained fixed machineKey values​​that were the same across multiple customer installations. This meant that if an attacker obtained the keys from a single installation, they could potentially target any other publicly accessible implementation of the platform.

The attackers created malicious ViewState payloads and sent them via HTTP requests in the __VIEWSTATE parameter. The server, believing the data to be valid, deserialized it and executed the embedded malicious code.

KnowledgeDeliver LMS: Vulnerability allows RCE attacks

The installation of the Godzilla web shell and the next phase of the attack

After the successful breach, the attackers installed the Godzilla web shell, also known as BLUEBEAM. This is a sophisticated tool remote administration that allows cybercriminals to execute commands, transfer files, and deploy additional malware within the compromised environment.

Researchers also detected privilege escalation actions, with the attackers modifying access permissions on the web server to gain full control over the application folders. This move allowed them to tamper with the platform's JavaScript files without being immediately detected.

See also: LiteSpeed ​​cPanel Plugin: Critical vulnerability actively exploited

This was the turning point of the attack, as the attackers embedded malicious code that displayed fake security alerts to the platform’s visitors. Users were encouraged to download a so-called “security authentication plugin,” which in reality acted as a means of infecting their systems .

Cobalt Strike Beacon and targeted attacks

The final phase of the attack involved the distribution of Cobalt Strike Beacon, a tool widely used by both professional penetration testers and cybercrime teams. Through Beacon, attackers can gain permanent access to a network, move laterally to other devices, and extract sensitive data.

Of particular interest is the fact that the malicious payload was encrypted with information related to the name of the targeted organization. According to Google, this indicates that the attacks were not mass, but designed specifically for specific organizations.

This practice is an indication of advanced operational preparation and points to attackers with a high level of technical training.

KnowledgeDeliver LMS: Vulnerability allows RCE attacks

The dangers of shared “secrets” on corporate platforms

The KnowledgeDeliver case highlights once again one of the biggest risks in modern software development: the use of shared credentials and predefined security secrets across multiple installations.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Critical vulnerability in Cisco Secure Workload – Update immediately

A single machineKey leak can turn an entire customer ecosystem into an easy target for large-scale attacks. Security experts emphasize that every enterprise application deployment should use unique encryption keys, strong monitoring mechanisms , and continuous monitoring of endpoint behavior.

As LMS platforms are now used by universities, companies, and public organizations, such attacks demonstrate that cybersecurity in digital education is becoming a critical issue for the entire technology ecosystem.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS