CVE-2026-39385: Frappe LMS enrollment bypass in paid courses via unrelated batch
Published Jul 20, 2026
·Updated
Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated batch. This has been patched in 2.52.0 with enrollment now validating that the batch is linked to course.
Affected Software
2 affected components
Frappe Frappe LMS<=2.51.0
Frappe Frappe LMS=2.52.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Frappe LMSto a version that resolves this vulnerability.Fixed in 2.52.0
Event History
Jul 20, 2026
CVE Published
via MITRE·04:55 PM
Data Sourced
via MITRE·04:55 PM
DescriptionWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-39385?
The severity of CVE-2026-39385 is high with a CVSS score of 7.1.
2
How do I fix CVE-2026-39385?
To fix CVE-2026-39385, update Frappe LMS to version 2.52.0 or later.
3
What does CVE-2026-39385 affect?
CVE-2026-39385 affects the Frappe LMS software prior to version 2.52.0.
4
What issue is caused by CVE-2026-39385?
CVE-2026-39385 allows users to bypass payment validation for paid courses by using an unrelated batch.
5
When was CVE-2026-39385 published?
CVE-2026-39385 was published on July 20, 2026.