Authorization Bypass in Dolibarr Affects Project Management Features
CVE-2026-73692
5.3MEDIUM
What is CVE-2026-73692?
Dolibarr ERP/CRM contains an authorization bypass vulnerability in the clonetasks mass action feature. This vulnerability allows authenticated users with project creation permissions to illegally clone tasks into private projects, which they should not be able to access. An erroneous condition in the project membership check mistakenly allows unauthorized users the ability to set the authorization flag. By manipulating the user-controlled 'projectid' POST parameter, attackers can create task records in any restricted project, undermining project confidentiality and management controls.
Affected Version(s)
Dolibarr ERP/CRM 21.0.0
