Frappe Learning is a learning system that helps users structure their content. Starting in version 2.0.0 and prior to version 2.41.0, when admins revoked a role from the user, the effect was not immediate because of caching. The issue has been fixed in version 2.41.0 by ensuring the cache is cleared after roles are updated.
Cite this page
CVE-2025-64707. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2025-64707
Use CWE-863, Frappe vendor hub and Learning product page to widen CVE-2025-64707 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-34606, CVE-2026-26977 and CVE-2026-39415 for nearby disclosures in the same product family.