Path Traversal Vulnerability in Dolibarr EmailCollector Component
CVE-2026-81730

8.8HIGH

Key Information:

Vendor

Dolibarr

Status
Vendor
CVE Published:
27 August 2026

What is CVE-2026-81730?

A path traversal vulnerability exists in Dolibarr's EmailCollector component, where email attachments are saved using their original filenames. This allows an attacker to manipulate the filename, potentially leading to the upload of malicious files outside the restricted areas of the application. Specifically, the lack of sanitation on the filename enables unauthorized write access to locations on the filesystem that the application should not be allowed to access, thereby posing significant security risks, including data integrity compromise and unauthorized access to sensitive files.

Affected Version(s)

dolibarr 9.0.0 < 24.0.0

dolibarr 24.0.0

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Holmquist (HASP Labs)
.