CVE 1.3 LOW

Frappe LMS affected by unauthorised user was able to access the full list of batch enrolled students_CVE-2026-26031

1.3 / 10
LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U

Description

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.44.0, security issue was identified in Frappe Learning, where unauthorised users were able to access the full list of enrolled students (by email) in batches. This vulnerability is fixed in 2.44.0.

Basic Information

ID CVE-2026-26031
Source GitHub_M
Published Feb 11, 2026 at 21:32

Affected Product

Vendor frappe
Product lms
Version < 2.44.0
Affected Versions frappe lms < 2.44.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.