Sensitive Data Exposure in Dolibarr's Members REST API
CVE-2026-71511
Key Information:
Badges
What is CVE-2026-71511?
Dolibarr ERP & CRM prior to version 24.0.0 suffers from a sensitive data exposure vulnerability within the Members REST API. This allows authenticated attackers with member-read permissions to access bcrypt password verifiers by querying specific member endpoints. Unfiltered data output from both individual member and member list API endpoints exposes crypted password verifier fields, making them susceptible to offline cracking attempts. Implementing the latest update is critical for ensuring the security of user password data and maintaining the integrity of the application.
Affected Version(s)
dolibarr 0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
