Description
A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component TakePOS Module. Such manipulation leads to missing authorization. The attack may be performed from remote. The name of the patch is 8992ce8704da947b6abe7b65a6fe59aed736bb81. It is advisable to implement a patch to correct this issue.
Published: 2026-08-09
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This flaw resides in the TakePOS Module’s invoice.php file and removes the required authorization step in the function fail. Attackers can invoke the vulnerable code remotely, creating or manipulating invoices without proper clearance.

Affected Systems

Dolibarr ERP users running any version up to and including 23.0.3 are affected.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score is not available. It is not listed in CISA KEV. The attack vector is inferred to be remote, as the vulnerability can be exercised over the network by accessing the invoice endpoint. Without remediation, an attacker could create or alter invoices and gain financial privileges.

Generated by OpenCVE AI on August 9, 2026 at 12:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the current Dolibarr ERP version and confirm it is less than or equal to 23.0.3
  • Apply the patch commit 8992ce8704da947b6abe7b65a6fe59aed736bb81 or upgrade to a newer release that includes the fix
  • Test that invoice access is restricted for non‑privileged users by attempting to invoke invoice.php fail functionality from a non‑admin account
  • Monitor system logs for any unauthorized invoice operations to confirm the patch effectiveness

Generated by OpenCVE AI on August 9, 2026 at 12:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 09 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component TakePOS Module. Such manipulation leads to missing authorization. The attack may be performed from remote. The name of the patch is 8992ce8704da947b6abe7b65a6fe59aed736bb81. It is advisable to implement a patch to correct this issue.
Title Dolibarr ERP TakePOS invoice.php fail authorization
First Time appeared Dolibarr
Dolibarr erp
Weaknesses CWE-862
CWE-863
CPEs cpe:2.3:a:dolibarr:erp:*:*:*:*:*:*:*:*
Vendors & Products Dolibarr
Dolibarr erp
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-09T10:45:10.818Z

Reserved: 2026-08-08T16:27:24.385Z

Link: CVE-2026-19350

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-09T12:30:17Z

Weaknesses