github.com
https://github.com/frappe/lms/releases/tag/v2.44.0 CVE-2026-26031
LOW
Frappe LMS affected by unauthorised user was able to access the full list of batch enrolled students
Record summary
CVE-2026-26031 has a selected CVSS score of 1.3 (low).
Description
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.44.0, security issue was identified in Frappe Learning, where unauthorised users were able to access the full list of enrolled students (by email) in batches. This vulnerability is fixed in 2.44.0.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 12, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | < 2.44.0 | affected |
References
2github.comConfirmation
https://github.com/frappe/lms/security/advisories/GHSA-3gw9-gwjm-vcq5