Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.44.0, security issue was identified in Frappe Learning, where unauthorised users were able to access the full list of enrolled students (by email) in batches. This vulnerability is fixed in 2.44.0.
References
| Link | Resource |
|---|---|
| https://github.com/frappe/lms/releases/tag/v2.44.0 | Product Release Notes |
| https://github.com/frappe/lms/security/advisories/GHSA-3gw9-gwjm-vcq5 | Vendor Advisory |
Configurations
History
12 Feb 2026, 17:11
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:frappe:learning:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
| First Time |
Frappe
Frappe learning |
|
| References | () https://github.com/frappe/lms/releases/tag/v2.44.0 - Product, Release Notes | |
| References | () https://github.com/frappe/lms/security/advisories/GHSA-3gw9-gwjm-vcq5 - Vendor Advisory |
11 Feb 2026, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-11 22:15
Updated : 2026-02-12 17:11
NVD link : CVE-2026-26031
Mitre link : CVE-2026-26031
CVE.ORG link : CVE-2026-26031
JSON object : View
Products Affected
frappe
- learning
CWE
CWE-863
Incorrect Authorization
