CVE-2026-26977: Frappe Learning

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.44.0 and below, unauthorized users are able to access the details of unpublished courses via API endpoints. A fix for this issue is planned for the 2.45.0 release.

Affected products

  • Frappe Learning: from 2.0.0, before 2.45.0 (fixed in 2.45.0)

Published 2026-02-20. Last modified 2026-06-17.