CVE-2026-39385
Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses b
CVSS
—
No CVSS
EPSS
0.4%
p31
KEV
—
Exploit Today
9
0-100
Published: Jul 20, 2026 · Last modified: Jul 22, 2026 · CWE-288
0.2%EPSS · 30 days0.4%
2026-08-222026-09-19
Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated batch. This has been patched in 2.52.0 with enrollment now validating that the batch is linked to course.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-621019.8 CRI34.4%
——10Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.2dCVE-2026-14917—51.5%
——15A SAML authentication bypass vulnerability affects the Kong SAML plugin when the validate_assertion_signature option is explicitly set to false. This option is enabled by default. When disabled, the plugin may extract the SAML identity from an unsigned assertion and authenticate the user without verifying a valid cryptographic signature.
As a result, an unauthenticated remote attacker may be able to submit a crafted SAML response and impersonate arbitrary users, including administrators1dCVE-2026-275469.8 CRI59.8%
——18An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.3dCVE-2026-571348.2 HIG23.5%
——7PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src/praisonai-ts/src/mcp/security.ts invokes the configured credential validator only when AuthMethod is api-key or bearer. Basic and OAuth policies accept any non-empty Authorization header without calling auth.validate(), then return an authenticated result, allowing callers with invalid credentials to access MCP tools and resources protected by those policies. This issue is fixed in version 1.7.2.5dCVE-2026-911437.2 HIG19.3%
——6goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated clients to bypass credential requirements. Attackers can issue CONNECT requests to establish tunnels through the authenticated proxy without providing credentials, enabling arbitrary TCP traffic relay and access to restricted destinations.4dCVE-2026-88260—10.1%
——3Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input vulnerability in Brainzcompany Zenius EMS 8.0 allows Remote Code Inclusion.
This issue affects Zenius EMS 8.0: through OAM (Build 109).1d