Local File Inclusion in Dolibarr ERP and CRM Software
CVE-2026-34036
6.5MEDIUM
What is CVE-2026-34036?
Dolibarr, an enterprise resource planning and customer relationship management software, is exposed to a Local File Inclusion vulnerability affecting versions 22.0.4 and earlier. This vulnerability arises from a flawed logic in the access control mechanism within the core AJAX endpoint /core/ajax/selectobject.php. An authenticated user lacking specific privileges can exploit this flaw by manipulating the objectdesc parameter, potentially allowing them to read sensitive non-PHP files, including configuration files and logs, which could lead to information leaks. Currently, there are no publicly available patches addressing this vulnerability.
Affected Version(s)
dolibarr <= 22.0.4
