Dolibarr Erp · Takepos Module · CVE-2026-19350
**Name of the Vulnerable Software and Affected Versions**
Dolibarr ERP versions prior to 23.0.4
**Description**
A remote issue exists in the TakePOS Module within the `fail()` function of the `htdocs/takepos/invoice.php` file. This flaw allows for missing authorization, enabling a remote attacker to bypass security checks.
**Recommendations**
Apply patch 8992ce8704da947b6abe7b65a6fe59aed736bb81 to resolve the issue.
As a temporary mitigation, restrict access to the `fail()` function in the `htdocs/takepos/invoice.php` file.