Authorization Bypass in Dolibarr ERP Affects User Notes Handler
CVE-2026-78160
5.3MEDIUM
What is CVE-2026-78160?
An authorization bypass vulnerability exists in Dolibarr ERP affecting versions up to 18.0.10, 22.0.5, and 23.0.3, specifically in the User Notes Handler component. The vulnerability is triggered by manipulating the ID argument in the /user/note.php file, allowing unauthorized access. This issue can be exploited remotely, making it critical for users to upgrade to versions 23.0.4 and 24.0.0 to secure their systems. The patch identifier for this fix is 9b5229ef3a9b58d00252d327936b022fb739f149.
Affected Version(s)
ERP 18.0.0
ERP 18.0.1
ERP 18.0.2
