Payment Bypass Vulnerability in Frappe LMS by Frappe Technologies
CVE-2026-39385
7.1HIGH
What is CVE-2026-39385?
Frappe LMS, an open-source learning management system developed by Frappe Technologies, contains a vulnerability in versions 2.51.0 and earlier that allows users to bypass payment validation for course enrollments. This issue arises when users manipulate the batch linked to the course, unintentionally permitting access to paid courses without proper validation. The vulnerability has been addressed in version 2.52.0, which ensures that enrollment checks are correctly linked to the course batch, thereby reinforcing the integrity of the payment process. For more information and details on how to mitigate this issue, refer to the official advisory.
Affected Version(s)
lms <= 2.51.0
