Frappé Technologies · Frappe · CVE-2026-29077
**Name of the Vulnerable Software and Affected Versions**
Frappe versions prior to 15.98.0
Frappe versions prior to 14.100.0
**Description**
Frappe is a full-stack web application framework. A flaw exists due to insufficient validation during document sharing, potentially allowing a user to share a document with permissions exceeding their own access rights.
**Recommendations**
Update to Frappe version 15.98.0 or later.
Update to Frappe version 14.100.0 or later.