Security Flaw in Dolibarr ERP CRM Affecting Online Signature Module
CVE-2026-7689
Key Information:
Badges
What is CVE-2026-7689?
A significant security flaw has been identified in Dolibarr ERP CRM, specifically within the Online Signature Module. The issue resides in the function dol_verifyHash located in the library htdocs/core/lib/security.lib.php. This flaw leads to inadequate verification of cryptographic signatures, which could allow remote attackers to exploit the vulnerability for malicious purposes. Although the complexity of the attack is high and exploitability is deemed difficult, the public availability of the exploit poses a threat. It is noteworthy that early disclosure attempts to the vendor received no response.
Affected Version(s)
ERP CRM 23.0.0
ERP CRM 23.0.1
ERP CRM 23.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
