CVE-2026-81730 CVE-2026-71504 CVE-2026-81728 CVE-2026-71506 CVE-2026-71505 CVE-2026-71507 CVE-2026-71508 CVE-2026-71509 CVE-2026-71510 CVE-2026-71511
Dolibarr 24.0.0 fixes path traversal, SQL injection and REST API authorization flaws
Dolibarr before 24.0.0 is affected by ten high-severity flaws: unauthenticated path traversal via EmailCollector attachments, SQL injection in import and user APIs, and REST API authorization bypasses affecting passwords, payments, bank details and payroll. Upgrade to 24.0.0.
What happened
Dolibarr's week 35 2026 security advisories cover ten high-severity vulnerabilities fixed in version 24.0.0. The most exposed is CVE-2026-81730, an unauthenticated path traversal in the EmailCollector module: any sender who can email a mailbox monitored by EmailCollector can use a crafted attachment filename to write attacker-controlled content outside the per-object attachment directory. Under Dolibarr's hardened layout, the write is confined to the documents tree and can corrupt or forge other objects' documents; where htdocs is writable, it reaches a web-executable path. The CVSS 4.0 score is 8.8.
The remaining nine require a Dolibarr account but only limited rights. CVE-2026-81728 injects SQL through the CSV and XLSX import update keys for a user holding import permission. CVE-2026-71510 does so through the users REST API filter for a user with user-read rights. CVE-2026-71504 allows member-creation rights to reset any user's password, including the administrator. Other flaws let a user with third-party creation rights replace a company's WebPortal password (CVE-2026-71505) or bank account details (CVE-2026-71507); invoice-deletion rights delete any payment record (CVE-2026-71506); user-write rights change payroll fields (CVE-2026-71508); and expense-creation rights bypass approval workflows (CVE-2026-71509). CVE-2026-71511 exposes bcrypt password verifiers through member endpoints. The CVE records do not state active exploitation or public disclosure.
Who is affected
Dolibarr versions 9.0.0 through 23.0.4 are affected by CVE-2026-81730. All Dolibarr versions before 24.0.0 are affected by the other nine vulnerabilities. This includes instances that run the EmailCollector module on a support or ticket inbox, and any deployment that exposes the REST API to users or integrations. The usual exposure is an internet-reachable Dolibarr instance or one where lower-privileged users can reach the API endpoints.
What to do now
- Upgrade to Dolibarr 24.0.0, which is the fixed version for all ten vulnerabilities.
- No workaround has been published by Dolibarr. Until the upgrade is complete, restrict network access to the Dolibarr application, especially the EmailCollector mailboxes and REST API endpoints, to trusted hosts and users.
- Review accounts and API keys with import, member, user, expense, third-party creation, or invoice-deletion permissions, and reduce or suspend them if they are not needed.
- After the upgrade, check for unexpected password resets, changed bank account or payroll fields, expense reports approved without timestamps, and attachment files outside the expected EmailCollector directories.
How to detect it
Dolibarr has not published indicators of compromise. Review for unexpected password resets, changes to bank account or payroll fields, expense reports approved without approval timestamps, and attachment files stored outside EmailCollector per-object directories.
Beyond the patch
This cluster matters because several flaws need only low-privileged accounts to reach financial and payroll data, and one needs no account at all. A penetration test and hardening exercise would surface injection and authorization gaps like these before an attacker uses them — Implementation & Assessment Services. Tracking Dolibarr's release cycle as part of supplier risk management shortens the gap between upstream fix and your own upgrade — Supply Chain Defense & Third-Party Risk.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| CVE-2026-81730 dolibarr | 9.0.0 – < 24.0.0 | 24.0.0 |
| CVE-2026-71504, CVE-2026-81728, CVE-2026-71506, CVE-2026-71505, CVE-2026-71507, CVE-2026-71508, CVE-2026-71509, CVE-2026-71510, CVE-2026-71511 dolibarr | – < 24.0.0 | 24.0.0 |
References
Patch and release notes
- github.com/Dolibarr/dolibarr/blob/23.0.4/htdocs/emailcollector/lib/emailcollector.lib.p…
- VulnCheck Advisory: Dolibarr 9.0.0 through 23.0.4 Path Traversal via EmailCollector Att…
- Patch Commit
- VulnCheck Advisory: Dolibarr before 24.0.0 SQL Injection via the CSV and XLSX Import Up…
- Patch Commit
- Patch Commit
- Patch Commit
- Patch Commit
Exploit and analysis
Other
- github.com/Dolibarr/dolibarr
- www.vulncheck.com/advisories/dolibarr-members-rest-api-improper-authorization-via-passw…
- github.com/Dolibarr/dolibarr/blob/23.0.4/htdocs/core/modules/import/import_csv.modules.…
- www.vulncheck.com/advisories/dolibarr-payments-rest-api-improper-authorization-via-dele…
- www.vulncheck.com/advisories/dolibarr-rest-api-broken-object-level-authorization-via-th…
- www.vulncheck.com/advisories/dolibarr-rest-api-broken-object-level-authorization-via-ba…
- www.vulncheck.com/advisories/dolibarr-rest-api-improper-authorization-via-user-update-e…
- www.vulncheck.com/advisories/dolibarr-expense-report-rest-api-improper-authorization-vi…
CVE
- CVE-2026-81730 — cve.org
- CVE-2026-81730 — NVD
- EUVD-2026-67235 — ENISA EUVD
- CVE-2026-71504 — cve.org
- CVE-2026-71504 — NVD
- EUVD-2026-65076 — ENISA EUVD
- CVE-2026-81728 — cve.org
- CVE-2026-81728 — NVD
- EUVD-2026-67233 — ENISA EUVD
- CVE-2026-71506 — cve.org
- CVE-2026-71506 — NVD
- EUVD-2026-65079 — ENISA EUVD
- CVE-2026-71505 — cve.org
- CVE-2026-71505 — NVD
- EUVD-2026-65078 — ENISA EUVD
- CVE-2026-71507 — cve.org
- CVE-2026-71507 — NVD
- EUVD-2026-65080 — ENISA EUVD
- CVE-2026-71508 — cve.org
- CVE-2026-71508 — NVD
- EUVD-2026-65081 — ENISA EUVD
- CVE-2026-71509 — cve.org
- CVE-2026-71509 — NVD
- EUVD-2026-65082 — ENISA EUVD
- CVE-2026-71510 — cve.org
- CVE-2026-71510 — NVD
- EUVD-2026-65083 — ENISA EUVD
- CVE-2026-71511 — cve.org
- CVE-2026-71511 — NVD
- EUVD-2026-65084 — ENISA EUVD