Skip to content

Unauthorised user was able to access the full list of batch enrolled students

Low
raizasafeel published GHSA-3gw9-gwjm-vcq5 Feb 11, 2026

Package

lms (frappe)

Affected versions

2.0.0

Patched versions

2.45.0

Description

Description

A security issue was identified in Frappe Learning, where unauthorised users were able to access the full list of enrolled students (by email) in batches.

Mitigation

This issue has been fixed, student list is now only returned to users who can create batches (Moderator / Batch Evaluator roles). All other users receive an empty list.

Acknowledgement

This issue was reported by @filime

Severity

Low

CVE ID

CVE-2026-26031

Weaknesses

No CWEs