Path Traversal Vulnerability in Dolibarr EmailCollector Component
CVE-2026-81730
8.8HIGH
What is CVE-2026-81730?
A path traversal vulnerability exists in Dolibarr's EmailCollector component, where email attachments are saved using their original filenames. This allows an attacker to manipulate the filename, potentially leading to the upload of malicious files outside the restricted areas of the application. Specifically, the lack of sanitation on the filename enables unauthorized write access to locations on the filesystem that the application should not be allowed to access, thereby posing significant security risks, including data integrity compromise and unauthorized access to sensitive files.
Affected Version(s)
dolibarr 9.0.0 < 24.0.0
dolibarr 24.0.0
