CVE-2026-26977

Severity CVSS v4.0:
MEDIUM
Type:
CWE-284 Improper Access Control
Publication date:
20/02/2026
Last modified:
20/02/2026

Description

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.44.0 and below, unauthorized users are able to access the details of unpublished courses via API endpoints. A fix for this issue is planned for the 2.45.0 release.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:frappe:learning:*:*:*:*:*:*:*:* 2.0.0 (including) 2.45.0 (excluding)