Arbitrary Code Execution Vulnerability in Dolibarr ERP/CRM by Dolibarr
CVE-2026-37711
7.3HIGH
What is CVE-2026-37711?
A vulnerability in Dolibarr ERP/CRM versions 22.0.0 to 22.0.4, and 24.0.0-alpha allows a remote attacker to execute arbitrary code through a flaw in the htdocs/core/actions_addupdatedelete.inc.php file. If exploited, this could enable an attacker to take control of the system, compromising sensitive data and potentially leading to further attacks.
