CVE-2026-39598: Kodezen Llc Academy Lms Pro

High severity, CVSS 8.0. EPSS: 0.4% chance of exploitation in the next 30 days.

Unrestricted Upload of File with Dangerous Type vulnerability in Kodezen LLC Academy LMS Pro allows Upload a Web Shell to a Web Server. This issue affects Academy LMS Pro: from n/a before 3.5.2.

Affected products

  • Kodezen Llc Academy Lms Pro: before 3.5.2 (fixed in 3.5.2)

Published 2026-06-17. Last modified 2026-06-17.