Improper Authorization Vulnerability in Dolibarr Members REST API
CVE-2026-71504
Key Information:
Badges
What is CVE-2026-71504?
Dolibarr ERP & CRM prior to version 24.0.0 is susceptible to an improper authorization flaw within the Members REST API. This vulnerability enables attackers who possess member-creation rights to reset the passwords of any user account, including sensitive accounts like that of the system administrator. By sending a request with a user account identifier and a new password without the requisite password-change permissions, attackers can replace valid user credentials. This allows them to instantly lock out legitimate users, posing a significant security risk.
Affected Version(s)
dolibarr 0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
