Broken Object-Level Authorization Vulnerability in Dolibarr REST API
CVE-2026-71505
Key Information:
Badges
What is CVE-2026-71505?
Dolibarr versions prior to 24.0.0 are susceptible to a broken object-level authorization flaw in their REST API. This vulnerability permits authenticated attackers, who possess third-party creation rights, to manipulate the WebPortal passwords of enterprises by circumventing access checks that are applied exclusively to read requests. By exploiting the write endpoint, attackers can replace a victim company's WebPortal password, subsequently gaining unauthorized access to sensitive invoice data and the previous password verifier from the API response, thereby facilitating an account takeover.
Affected Version(s)
dolibarr 0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
