CVE-2026-26977 – Frappe Learning Management System exposes details of unpublished courses to unauthorized users
CVE ID : CVE-2026-26977
Published : Feb. 20, 2026, 2:16 a.m. | 44 minutes ago
Description : Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.44.0 and below, unauthorized users are able to access the details of unpublished courses via API endpoints. A fix for this issue is planned for the 2.45.0 release.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more…