Broken Object-Level Authorization in Dolibarr's REST API
CVE-2026-71507
Key Information:
Badges
What is CVE-2026-71507?
Dolibarr ERP & CRM prior to version 24.0.0 is susceptible to a broken object-level authorization vulnerability within its REST API. This flaw allows authenticated attackers who possess permissions for third-party creation to illicitly create, modify, or remove bank account information for any company, irrespective of the required access rights. The vulnerability specifically affects the bank account write routes and permits the injection of arbitrary IBANs as creditor accounts. Consequently, this can result in the erroneous rerouting of SEPA credit-transfer files, channeling funds to accounts controlled by the attacker.
Affected Version(s)
dolibarr 0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
