Remote Code Execution Vulnerability in Dolibarr ERP/CRM by Dolibarr
CVE-2026-37713

Currently unrated

Key Information:

Vendor

Dolibarr

Vendor
CVE Published:
27 May 2026

What is CVE-2026-37713?

A vulnerability in Dolibarr ERP/CRM versions 22.0.0 to 22.0.4 and 24.0.0-alpha permits remote attackers to execute arbitrary code through the 'htdocs/core/class/commonobject.class.php' file. This flaw can have serious implications for affected systems, posing a risk to data integrity and system security. Proper updates and security measures should be implemented to mitigate this risk.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.