Local File Inclusion in Dolibarr ERP and CRM Software
CVE-2026-34036

6.5MEDIUM

Key Information:

Vendor

Dolibarr

Status
Vendor
CVE Published:
31 March 2026

What is CVE-2026-34036?

Dolibarr, an enterprise resource planning and customer relationship management software, is exposed to a Local File Inclusion vulnerability affecting versions 22.0.4 and earlier. This vulnerability arises from a flawed logic in the access control mechanism within the core AJAX endpoint /core/ajax/selectobject.php. An authenticated user lacking specific privileges can exploit this flaw by manipulating the objectdesc parameter, potentially allowing them to read sensitive non-PHP files, including configuration files and logs, which could lead to information leaks. Currently, there are no publicly available patches addressing this vulnerability.

Affected Version(s)

dolibarr <= 22.0.4

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.