CVE-2026-78160

Summary

A vulnerability has been found in Dolibarr ERP up to 18.0.10/22.0.5/23.0.3. This issue affects some unknown processing of the file /user/note.php of the component User Notes Handler. The manipulation of the argument ID leads to authorization bypass. The attack can be initiated remotely. Upgrading to version 23.0.4 and 24.0.0 is capable of addressing this issue. The identifier of the patch is 9b5229ef3a9b58d00252d327936b022fb739f149. Upgrading the affected component is advised.

Affected Software

VendorProductVersion RangeStatus
DolibarrERP18.0.0affected
DolibarrERP18.0.1affected
DolibarrERP18.0.2affected
DolibarrERP18.0.3affected
DolibarrERP18.0.4affected
DolibarrERP18.0.5affected
DolibarrERP18.0.6affected
DolibarrERP18.0.7affected
DolibarrERP18.0.8affected
DolibarrERP18.0.9affected
DolibarrERP18.0.10affected
DolibarrERP22.0.0affected
DolibarrERP22.0.1affected
DolibarrERP22.0.2affected
DolibarrERP22.0.3affected
DolibarrERP22.0.4affected
DolibarrERP22.0.5affected
DolibarrERP23.0.0affected
DolibarrERP23.0.1affected
DolibarrERP23.0.2affected
DolibarrERP23.0.3affected
DolibarrERP23.0.4unaffected
DolibarrERP24.0.0unaffected

Weaknesses

  • CWE-639: Authorization Bypass
  • CWE-285: Improper Authorization

References