Authorization Bypass in Dolibarr Users Management API
CVE-2026-82633

5.3MEDIUM

Key Information:

Vendor

Dolibarr

Status
Vendor
CVE Published:
30 August 2026

What is CVE-2026-82633?

Dolibarr versions 10.0.0 through 23.0.4 are susceptible to a flaw where the Users::getGroups REST API endpoint fails to enforce adequate per-object authorization. This oversight permits authenticated users to exploit the API by utilizing arbitrary user identifiers in the GET /users/{id}/groups call. Consequently, this grants attackers unauthorized access to sensitive information, including group memberships, entity associations, and private notes, potentially violating data confidentiality across different user tenants. It is essential for administrators to update to version 24.0.0 or later to mitigate this vulnerability effectively.

Affected Version(s)

dolibarr 10.0.0 < 24.0.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Holmquist (Hasp Labs)
.