PT-2026-81011 · Dolibarr+1 · Dolibarr+1

·

CVE-2026-77923

·

Published

2026-08-24

·

Updated

2026-08-24

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Dolibarr versions 21.0.0 through 23.x
Description An authorization bypass exists due to an inverted boolean condition in the private-project membership check. This occurs within the clonetasks mass action handler located in htdocs/core/actions massactions.inc.php. Authenticated users who possess project creation permissions, but lack access to a specific private project, can exploit the flawed !in array() check to clone tasks into unauthorized private projects.
Recommendations Update to version 24.0.0 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77923

Affected Products

Dolibarr
Dolibarr Erp/Crm