CVE-2026-26977
20.02.2026, 02:16
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.44.0 and below, unauthorized users are able to access the details of unpublished courses via API endpoints. A fix for this issue is planned for the 2.45.0 release.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| frappe | learning | 2.0.0 ≤ 𝑥 < 2.45.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration