CVE-2026-89013 CVE-2026-89012
Dolibarr 23.0.4–24.0.0 authorization and SQL filter bypasses expose files and password hashes (CVE-2026-89013, CVE-2026-89012)
Dolibarr 24.0.1 fixes two high-severity flaws: an unauthenticated file-read authorization bypass (CVE-2026-89013) and an authenticated SQL filter denylist bypass that recovers password hashes (CVE-2026-89012). Update from 23.0.4 through 24.0.0 to 24.0.1.
What happened
Dolibarr's 24.0.1 release fixes two flaws. CVE-2026-89013 is an authorization bypass (CWE-863) in htdocs/document.php and htdocs/viewimage.php. An unauthenticated attacker can send a request with the hashp parameter set to shared, which skips token validation while satisfying the authorization condition. A successful request can read application logs, uploaded business documents, database backups containing password hashes, and files belonging to other multicompany entities. The CVSS 4.0 score is 8.7 (high), with a network attack vector, low complexity, no privileges and no user interaction required.
CVE-2026-89012 affects Dolibarr 24.0.0 and stems from a case-sensitive denylist in the sqlfilters API query parameter. An authenticated attacker can submit uppercase variants of protected field names. Because database column resolution is case-insensitive, the denylist check is bypassed and prefix-matching predicates act as a boolean oracle to extract password hashes, including those for administrator accounts. The CVSS 4.0 score is 7.1 (high). Neither flaw is listed in CISA KEV, and no exploitation or public disclosure is recorded.
Who is affected
CVE-2026-89013 affects Dolibarr 23.0.4 to before 24.0.1. CVE-2026-89012 affects Dolibarr 24.0.0 to before 24.0.1. In practice, update any instance from 23.0.4 through 24.0.0. Dolibarr is an open-source ERP/CRM platform that is often self-hosted and internet-facing, holding customer, supplier and business documents.
What to do now
- Update to Dolibarr 24.0.1. This release fixes both CVE-2026-89013 and CVE-2026-89012.
- If you cannot update immediately, restrict network access to document.php and viewimage.php and the authenticated API. No workaround has been published by the vendor.
- After updating, treat files and password hashes that the file-read flaw could have exposed as potentially compromised and reset relevant credentials, especially for high-privilege Dolibarr users and any secrets stored in uploaded documents.
How to detect it
Dolibarr has not published indicators of compromise. Review web server access logs for requests to document.php or viewimage.php with a hashp parameter set to shared, and API logs for sqlfilters parameters containing uppercase variants of protected field names or repeated prefix-matching queries against user tables. Since no exploitation is recorded, treat these as hunting leads rather than confirmed indicators.
Beyond the patch
Beyond patching, CVE-2026-89013 is a reminder that self-hosted Dolibarr deployments often expose document and image endpoints to the internet unnecessarily. Virtual CISO Services can help identify and reduce that exposure, and Implementation & Assessment Services can test and harden a Dolibarr deployment before go-live or after major changes. If a supplier runs Dolibarr for you, tracking their patch response is part of Supply Chain Defense & Third-Party Risk.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| CVE-2026-89013 Dolibarr | 23.0.4 – < 24.0.1 | 24.0.1 |
| CVE-2026-89012 Dolibarr | 24.0.0 – < 24.0.1 | 24.0.1 |