Incorrect Authorization Vulnerability in Dolibarr ERP CRM
CVE-2026-107706
5.3MEDIUM
What is CVE-2026-107706?
Dolibarr ERP CRM prior to version 24.0.2 contains an incorrect authorization issue within the updateextrafield.php script. This flaw allows authenticated users with read-only permissions to send POST requests that could modify extrafield values related to third parties, products, members, projects, or contacts. As a result, it may enable unauthorized changes to otherwise protected data. Users are advised to upgrade to version 24.0.2 or later to mitigate this vulnerability.
Affected Version(s)
dolibarr 0 < 24.0.2
dolibarr 24.0.2
