SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-39385

HIGH · CVSS 7.1 EPSS 0.22% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

Frappe LMS versions 2.51.0 and earlier are vulnerable to a payment validation bypass, allowing users to enroll in courses without proper payment by exploiting unrelated batches. This flaw could lead to unauthorized access to course materials and potential revenue loss for educational institutions. Organizations using affected versions should prioritize upgrading to 2.52.0 or later to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-39385
Severity
HIGH
CVSS
7.1
EPSS
0.22%

Original NVD Description

Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated batch. This has been patched in 2.52.0 with enrollment now validating that the batch is linked to course.