Authorization Bypass in Dolibarr ERP Affects User Notes Handler
CVE-2026-78160

5.3MEDIUM

Key Information:

Vendor

Dolibarr

Status
Vendor
CVE Published:
24 August 2026

What is CVE-2026-78160?

An authorization bypass vulnerability exists in Dolibarr ERP affecting versions up to 18.0.10, 22.0.5, and 23.0.3, specifically in the User Notes Handler component. The vulnerability is triggered by manipulating the ID argument in the /user/note.php file, allowing unauthorized access. This issue can be exploited remotely, making it critical for users to upgrade to versions 23.0.4 and 24.0.0 to secure their systems. The patch identifier for this fix is 9b5229ef3a9b58d00252d327936b022fb739f149.

Affected Version(s)

ERP 18.0.0

ERP 18.0.1

ERP 18.0.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abderrahmane Aksoum (VulDB User)
.