CVE-2026-39385

Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated batch. This has been patched in 2.52.0 with enrollment now validating that the batch is linked to course.
CVSS

No CVSS.

Configurations

No configuration.

History

20 Jul 2026, 17:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-20 17:17

Updated : 2026-07-22 20:50


NVD link : CVE-2026-39385

Mitre link : CVE-2026-39385

CVE.ORG link : CVE-2026-39385


JSON object : View

Products Affected

No product.

CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel