PT-2026-79794 · Unknown · Dolibarr Erp

·

CVE-2026-78160

·

Published

2026-08-24

·

Updated

2026-08-24

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Dolibarr ERP versions prior to 18.0.11 Dolibarr ERP versions prior to 22.0.6 Dolibarr ERP versions prior to 23.0.4
Description An authorization bypass exists in the User Notes Handler component due to improper processing of the /user/note.php endpoint. A remote attacker can exploit this by manipulating the ID argument to bypass security checks.
Recommendations Update to version 23.0.4. Update to version 24.0.0. As a temporary mitigation, restrict access to the /user/note.php file.

Exploit

Fix

Improper Authorization

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78160

Affected Products

Dolibarr Erp