Authorization Bypass in Dolibarr Users Management API
CVE-2026-82633
5.3MEDIUM
What is CVE-2026-82633?
Dolibarr versions 10.0.0 through 23.0.4 are susceptible to a flaw where the Users::getGroups REST API endpoint fails to enforce adequate per-object authorization. This oversight permits authenticated users to exploit the API by utilizing arbitrary user identifiers in the GET /users/{id}/groups call. Consequently, this grants attackers unauthorized access to sensitive information, including group memberships, entity associations, and private notes, potentially violating data confidentiality across different user tenants. It is essential for administrators to update to version 24.0.0 or later to mitigate this vulnerability effectively.
Affected Version(s)
dolibarr 10.0.0 < 24.0.0
