Payment Bypass Vulnerability in Frappe LMS by Frappe Technologies
CVE-2026-39385

7.1HIGH

Key Information:

Vendor

Frappe

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-39385?

Frappe LMS, an open-source learning management system developed by Frappe Technologies, contains a vulnerability in versions 2.51.0 and earlier that allows users to bypass payment validation for course enrollments. This issue arises when users manipulate the batch linked to the course, unintentionally permitting access to paid courses without proper validation. The vulnerability has been addressed in version 2.52.0, which ensures that enrollment checks are correctly linked to the course batch, thereby reinforcing the integrity of the payment process. For more information and details on how to mitigate this issue, refer to the official advisory.

Affected Version(s)

lms <= 2.51.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.