Sceawere

Vulnerability Detail

CVE-2026-78160UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Dolibarr ERP Authorization Bypass Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
2h ago
Vendor
Dolibarr
Product
ERP
Attack Type
Authorization Bypass
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability has been found in Dolibarr ERP up to 18.0.10/22.0.5/23.0.3. This issue affects some unknown processing of the file /user/note.php of the component User Notes Handler. The manipulation of the argument ID leads to authorization bypass. The attack can be initiated remotely. Upgrading to version 23.0.4 and 24.0.0 is capable of addressing this issue. The identifier of the patch is 9b5229ef3a9b58d00252d327936b022fb739f149. Upgrading the affected component is advised.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-08-24T01:16:57.180Z",
  "pubdate": "2026-08-24T01:16:57.180Z",
  "executiveSummary": "An authorization bypass vulnerability has been identified in Dolibarr ERP affecting the User Notes Handler component. Specifically, the flaw resides in the processing logic of the /user/note.php file, where improper handling of the ID argument allows unauthorized access to sensitive functionality. This security defect enables remote attackers to bypass access control mechanisms and interact with resources outside their authorized privilege level. The vulnerability poses significant risk to confidentiality and data integrity within enterprise deployments, potentially exposing sensitive user notes and internal operational data to malicious actors. Exploitation can be executed remotely over the network without requiring complex preliminary interactions, provided the target endpoint is reachable. The vulnerability impacts multiple stable release branches of Dolibarr ERP up to versions 18.0.10, 22.0.5, and 23.0.3. Organizations utilizing affected versions face heightened exposure to unauthorized data access until remedial actions are applied. Remediation requires immediate software upgrading to secure versions provided by the vendor, specifically versions 23.0.4, 24.0.0, or the application of the official patch identified by commit hash 9b5229ef3a9b58d00252d327936b022fb739f149.",
  "technicalDetails": "The vulnerability is an authorization bypass flaw located within the User Notes Handler component of Dolibarr ERP, specifically instantiated via the /user/note.php endpoint. The fundamental root cause stems from insufficient access control validation and inadequate validation of the ID argument submitted during HTTP requests to the vulnerable script. In secure application architectures, input parameters identifying specific user records must be rigorously validated against the session context and access control lists (ACLs) of the authenticated principal to ensure that the requester possesses the requisite permissions to access or modify the designated resource.\nDuring the exploitation flow, a remote attacker interacts with the /user/note.php script over the network. By manipulating the ID parameter within the HTTP request, the attacker bypasses the internal authorization checks designed to restrict access to user-specific notes. Because the application fails to adequately verify whether the current user context is authorized to view or process the note corresponding to the supplied ID, the underlying backend logic processes the request as if it originated from an authorized entity. This broken object-level authorization (BOLA) or missing function-level access control flaw allows unauthorized retrieval, manipulation, or processing of sensitive records managed by the User Notes Handler component.\nThe attack vector is network-exploitable, requiring remote access to the Dolibarr ERP web interface. Depending on the deployment configuration, exploitation may or may not require basic application authentication, but crucially subverts role-based access controls to perform actions exceeding the attacker's assigned privileges. The post-exploitation impact includes the unauthorized disclosure of confidential user notes, potential information leakage, and erosion of the application's access control boundary. Affected software versions include Dolibarr ERP up to 18.0.10, 22.0.5, and 23.0.3. The vulnerability is addressed in version 23.0.4 and version 24.0.0, incorporating the official patch designated by identifier 9b5229ef3a9b58d00252d327936b022fb739f149."
}
CVE-2026-78160: Dolibarr ERP Authorization Bypass Vulnerability (MEDIUM Severity, CVSS: 6.3) - Sceawere