Sceawere

Vulnerability Detail

CVE-2026-71507UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Dolibarr Broken Object-Level Authorization Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
Dolibarr
Product
dolibarr
Attack Type
Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account write routes that allows authenticated attackers with third-party creation rights to create, replace, or delete bank account details of any company without requiring read access to that company. Attackers can inject attacker-controlled IBANs as creditor accounts, which are then written into regenerated SEPA credit-transfer files, redirecting outgoing payments to attacker-controlled accounts.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-24T19:16:50.110Z",
  "pubdate": "2026-08-24T19:16:50.110Z",
  "executiveSummary": "Dolibarr before 24.0.0 suffers from a broken object-level authorization (BOLA) vulnerability located within the REST API company bank account write routes. This security flaw enables authenticated malicious actors possessing third-party creation rights to perform unauthorized creation, replacement, or deletion operations against the bank account details associated with any arbitrary company within the system, even when explicit read access to the target company is absent.\nThe primary business impact of this vulnerability involves financial fraud and fund redirection. An attacker can leverage this API flaw to inject attacker-controlled International Bank Account Numbers (IBANs) designated as creditor accounts. Consequently, these malicious entries are incorporated into subsequently regenerated SEPA credit-transfer files, effectively redirecting outbound organizational payments directly to attacker-controlled accounts.\nThe risk profile is elevated due to the capability for unauthorized financial modification via API endpoints exposed over the network. Exploitation requires authenticated access with specific third-party creation privileges, allowing low-privileged or restricted roles to escalate their impact to critical financial tampering without needing full administrative privileges or direct read permissions to victim corporate records.",
  "technicalDetails": "The root cause of the vulnerability resides in insufficient authorization checks within the Dolibarr REST API endpoints responsible for company bank account write operations. Specifically, the application fails to adequately validate whether the authenticated user possesses the appropriate permissions or relationship to access, modify, or delete the bank account resource of a specific target company object.\nThe vulnerable component consists of the REST API company bank account write routes in Dolibarr versions prior to 24.0.0. The attack surface is exposed via the application's network-accessible REST API interface, requiring the attacker to possess an authenticated session and permissions related to third-party entity creation.\nThe step-by-step attack flow proceeds as follows: First, the attacker authenticates to the Dolibarr REST API using credentials that grant third-party creation rights. Second, the attacker formulates an API request targeting the bank account write routes for a victim company identifier, bypassing standard authorization boundaries due to the missing access control checks. Third, the attacker submits a payload containing malicious banking details, specifically substituting legitimate creditor information with an attacker-controlled IBAN. Fourth, the system accepts and persists the unauthorized banking details against the target company record without verifying if the user has authorization over that specific object. Finally, during routine financial operations, the application generates SEPA credit-transfer files utilizing the newly injected, compromised IBANs.\nThe post-exploitation impact is characterized by the silent redirection of outbound financial transactions. Because the modified IBANs are written directly into regenerated SEPA credit-transfer files, subsequent payment runs automatically route funds to the adversary's accounts, resulting in direct financial loss and potential compromise of the organization's supply chain or vendor payment integrity."
}
CVE-2026-71507: Dolibarr Broken Object-Level Authorization Vulnerability (MEDIUM Severity, CVSS: 6.5) - Sceawere