Skip to content

CVE-2026-89013 CVE-2026-89012

Dolibarr 23.0.4–24.0.0 authorization and SQL filter bypasses expose files and password hashes (CVE-2026-89013, CVE-2026-89012)

High 8.7 Vendor: Dolibarr Published

Dolibarr 24.0.1 fixes two high-severity flaws: an unauthenticated file-read authorization bypass (CVE-2026-89013) and an authenticated SQL filter denylist bypass that recovers password hashes (CVE-2026-89012). Update from 23.0.4 through 24.0.0 to 24.0.1.

What happened

Dolibarr's 24.0.1 release fixes two flaws. CVE-2026-89013 is an authorization bypass (CWE-863) in htdocs/document.php and htdocs/viewimage.php. An unauthenticated attacker can send a request with the hashp parameter set to shared, which skips token validation while satisfying the authorization condition. A successful request can read application logs, uploaded business documents, database backups containing password hashes, and files belonging to other multicompany entities. The CVSS 4.0 score is 8.7 (high), with a network attack vector, low complexity, no privileges and no user interaction required.

CVE-2026-89012 affects Dolibarr 24.0.0 and stems from a case-sensitive denylist in the sqlfilters API query parameter. An authenticated attacker can submit uppercase variants of protected field names. Because database column resolution is case-insensitive, the denylist check is bypassed and prefix-matching predicates act as a boolean oracle to extract password hashes, including those for administrator accounts. The CVSS 4.0 score is 7.1 (high). Neither flaw is listed in CISA KEV, and no exploitation or public disclosure is recorded.

Who is affected

CVE-2026-89013 affects Dolibarr 23.0.4 to before 24.0.1. CVE-2026-89012 affects Dolibarr 24.0.0 to before 24.0.1. In practice, update any instance from 23.0.4 through 24.0.0. Dolibarr is an open-source ERP/CRM platform that is often self-hosted and internet-facing, holding customer, supplier and business documents.

What to do now

  1. Update to Dolibarr 24.0.1. This release fixes both CVE-2026-89013 and CVE-2026-89012.
  2. If you cannot update immediately, restrict network access to document.php and viewimage.php and the authenticated API. No workaround has been published by the vendor.
  3. After updating, treat files and password hashes that the file-read flaw could have exposed as potentially compromised and reset relevant credentials, especially for high-privilege Dolibarr users and any secrets stored in uploaded documents.

How to detect it

Dolibarr has not published indicators of compromise. Review web server access logs for requests to document.php or viewimage.php with a hashp parameter set to shared, and API logs for sqlfilters parameters containing uppercase variants of protected field names or repeated prefix-matching queries against user tables. Since no exploitation is recorded, treat these as hunting leads rather than confirmed indicators.

Beyond the patch

Beyond patching, CVE-2026-89013 is a reminder that self-hosted Dolibarr deployments often expose document and image endpoints to the internet unnecessarily. Virtual CISO Services can help identify and reduce that exposure, and Implementation & Assessment Services can test and harden a Dolibarr deployment before go-live or after major changes. If a supplier runs Dolibarr for you, tracking their patch response is part of Supply Chain Defense & Third-Party Risk.

Affected and fixed versions

ProductAffectedFixed in
CVE-2026-89013
Dolibarr
23.0.4 – < 24.0.124.0.1
CVE-2026-89012
Dolibarr
24.0.0 – < 24.0.124.0.1

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.