PT-2026-85389 · Dolibarr · Dolibarr

·

CVE-2026-85401

·

Published

2026-09-04

·

Updated

2026-09-04

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Dolibarr versions prior to 23.0.4
Description A weakness in the Legacy File Manager component, specifically within the file htdocs/core/filemanagerdol/connectors/php/config.inc.php, allows for improper access controls. This issue can be exploited remotely by executing a specific manipulation.
Recommendations Upgrade to version 23.0.4. Restrict access to the htdocs/core/filemanagerdol/connectors/php/config.inc.php file as a temporary mitigation measure.

Exploit

Fix

Incorrect Privilege Assignment

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85401

Affected Products

Dolibarr