Unauthorized Access Vulnerability in Frappe Learning Management System
CVE-2026-26031
1.3LOW
What is CVE-2026-26031?
In the Frappe Learning Management System, prior to version 2.44.0, a security vulnerability was identified that allowed unauthorized users to gain access to the complete list of enrolled students, including their email addresses, in batch formats. This significant data exposure risk poses a threat to student privacy and data integrity. The vulnerability was addressed in version 2.44.0, which users are urged to upgrade to in order to protect sensitive information.
Affected Version(s)
lms < 2.44.0
