File Write Vulnerability in Frappe Learning Management System
CVE-2026-39405

9.4CRITICAL

Key Information:

Vendor

Frappe

Status
Vendor
CVE Published:
20 May 2026

What is CVE-2026-39405?

The Frappe Learning Management System (LMS) versions up to 2.50.0 are vulnerable to a file write issue, where users with course editing privileges can upload SCORM ZIP packages that allow them to write files outside of the designated directory. This could lead to unauthorized file access and potential exposure of sensitive information. The vulnerability has been addressed in version 2.50.1, urging all users to update promptly to mitigate associated risks.

Affected Version(s)

lms < 2.50.1

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.