PT-2026-81001 · Dolibarr · Dolibarr

·

CVE-2026-71506

·

Published

2026-08-24

·

Updated

2026-08-25

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dolibarr versions prior to 24.0.0
Description An improper authorization issue exists in the payments REST API delete endpoint. Authenticated attackers with invoice-deletion rights can bypass the required payment-issuance rights check to permanently delete any payment record. This flaw allows attackers to zero out paid amounts on invoices and remove entries from accounting exports, leading to a loss of financial data integrity.
Recommendations Update to version 24.0.0 or later. Restrict API access to minimize the risk of exploitation.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71506

Affected Products

Dolibarr