Description
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that allows authenticated attackers with invoice-deletion rights to permanently delete any payment record by bypassing the intended payment-issuance rights check. Attackers can exploit this misconfigured permission check to zero paid amounts on invoices and remove entries from accounting exports, causing financial data integrity loss.
Published: 2026-08-24
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized deletion of payment records and loss of financial data integrity
Action: Apply patch
AI Analysis

Impact

Dolibarr versions before 24.0.0 contain a flaw in the payments REST API delete endpoint where a permission check for payment creation is incorrectly performed. Authenticated users who possess invoice‑deletion rights can delete any payment record regardless of the intended payment‑issuance permissions. This allows an attacker to zero paid amounts on invoices and remove entries from accounting exports, thereby compromising the integrity of financial data.

Affected Systems

The vulnerability affects all Dolibarr installations running any release earlier than 24.0.0. Users should verify the exact version of Dolibarr deployed, as the security update was released in the 24.0.0 milestone.

Risk and Exploitability

The CVSS score for this issue is 7.2, indicating a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers must be authenticated and hold invoice‑deletion privileges; no remote exploitation requirement is stated. Once these conditions are met, the attacker can permanently eliminate payment records and corrupt financial export data.

Generated by OpenCVE AI on August 24, 2026 at 20:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dolibarr to version 24.0.0 or later to receive the vendor fix for the improper authorization check.
  • Restrict the "invoice‑deletion" permission to only essential personnel and audit current user roles for over‑privileged accounts.
  • After the upgrade and permission hardening, perform an audit of payment records and accounting exports to detect any unauthorized deletions or inconsistencies.

Generated by OpenCVE AI on August 24, 2026 at 20:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Dolibarr
Dolibarr dolibarr
Vendors & Products Dolibarr
Dolibarr dolibarr

Mon, 24 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Description Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that allows authenticated attackers with invoice-deletion rights to permanently delete any payment record by bypassing the intended payment-issuance rights check. Attackers can exploit this misconfigured permission check to zero paid amounts on invoices and remove entries from accounting exports, causing financial data integrity loss.
Title Dolibarr < 24.0.0 Payments REST API Improper Authorization via Delete Endpoint
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Dolibarr Dolibarr
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-29T11:47:37.389Z

Reserved: 2026-08-06T20:42:17.834Z

Link: CVE-2026-71506

cve-icon Vulnrichment

Updated: 2026-08-26T15:46:19.265Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T19:16:49.960

Modified: 2026-09-08T20:23:49.880

Link: CVE-2026-71506

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:00:13Z

Weaknesses