CVE-2026-26977: Frappe Learning
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.44.0 and below, unauthorized users are able to access the details of unpublished courses via API endpoints. A fix for this issue is planned for the 2.45.0 release.
Affected products
- Frappe Learning: from 2.0.0, before 2.45.0 (fixed in 2.45.0)
Published 2026-02-20. Last modified 2026-06-17.