CVE-2026-39385

HIGH

Frappe LMS enrollment bypass in paid courses via unrelated batch

Title source: cna
STIX 2.1

Description

Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated batch. This has been patched in 2.52.0 with enrollment now validating that the batch is linked to course.

References (1)

Core 1
Core References

Scores

CVSS v4 7.1
EPSS 0.0022
EPSS Percentile 12.6%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-288
Status published
Products (1)
frappe/lms <= 2.51.0
Published Jul 20, 2026
Tracked Since Jul 20, 2026