7.1
CVE-2026-71505
- EPSS 0.23%
- Veröffentlicht 24.08.2026 19:00:47
- Zuletzt bearbeitet 08.09.2026 20:23:49
- Erkennungen
Dolibarr < 24.0.0 REST API Broken Object-Level Authorization via Third-Party Write Route
Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site account write routes that allows authenticated attackers with third-party creation rights to overwrite the WebPortal password of any company by bypassing per-object access checks that are only enforced on read routes. Attackers can replace the victim company's WebPortal password through the write endpoint, authenticate as that company to access its invoice data, and also obtain the victim's previous password verifier from the API response.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerDolibarr
≫
Produkt
dolibarr
Default Statusaffected
Version
0
Version <
24.0.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.139 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 7.1 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| disclosure@vulncheck.com | 7.1 | 2.8 | 4.2 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
|
CWE-639 Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
https://github.com/Dolibarr/dolibarr/releases/tag/24.0.0
https://codeant.ai/security-research/cve-2026-71505-dolibarr-bola-enables-portal-account-takeover
https://github.com/Dolibarr/dolibarr/commit/4cf305ebb958eeffa921aad7c94de179b764f7e7
https://www.vulncheck.com/advisories/dolibarr-rest-api-broken-object-level-authorization-via-third-party-write-route