Improper Authorization in Dolibarr Account Handler
CVE-2026-77686
Key Information:
Badges
What is CVE-2026-77686?
A vulnerability exists in Dolibarr versions up to 23.0.4, specifically within the Account Handler component located in htdocs/user/card.php. The issue arises from improper handling of the argument ID, allowing unauthenticated users to gain access to functionalities they should not be permitted to. This flaw can enable remote attackers to manipulate access controls, facilitating unauthorized actions within user accounts. To mitigate this vulnerability, users are advised to update to Dolibarr version 24.0.0, which includes the necessary patches.
Affected Version(s)
Dolibarr 23.0.0
Dolibarr 23.0.1
Dolibarr 23.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
