Authorization Bypass in Dolibarr Affects Project Management Features
CVE-2026-73692

5.3MEDIUM

Key Information:

Vendor

Dolibarr

Vendor
CVE Published:
18 August 2026

What is CVE-2026-73692?

Dolibarr ERP/CRM contains an authorization bypass vulnerability in the clonetasks mass action feature. This vulnerability allows authenticated users with project creation permissions to illegally clone tasks into private projects, which they should not be able to access. An erroneous condition in the project membership check mistakenly allows unauthorized users the ability to set the authorization flag. By manipulating the user-controlled 'projectid' POST parameter, attackers can create task records in any restricted project, undermining project confidentiality and management controls.

Affected Version(s)

Dolibarr ERP/CRM 21.0.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pavel Kohout, Aisle Research
.