Document Sharing Permission Flaw in Frappe Framework
CVE-2026-29077
7.1HIGH
What is CVE-2026-29077?
The Frappe Framework experienced a vulnerability that allowed users to share documents with permissions they did not possess. This lack of validation could lead to unauthorized access and exposure of sensitive information. The issue has been resolved in versions 15.98.0 and 14.100.0, which have implemented improved validation mechanisms to ensure users only share documents according to their actual permission levels.
Affected Version(s)
frappe < 15.98.0 < 15.98.0
frappe < 14.100.0 < 14.100.0
