Description
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update endpoint that allows attackers with user-write rights to modify payroll fields by exploiting an incomplete credential denylist that omits payroll columns. Attackers can rewrite salary, bonus, hourly rate, daily rate, and weekly hours for any user without holding payroll rights, with the modified values appearing in payroll export reports.
Published: 2026-08-24
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized payroll data alteration
Action: Patch Immediately
AI Analysis

Impact

Dolibarr versions prior to 24.0.0 contain an improper authorization flaw in the user REST API update endpoint. Attackers who possess generic user‑write rights but not payroll permissions can target the payroll fields in the update payload. By sending update requests that include salary, bonus, hourly rate, daily rate, or weekly hours, an attacker can rewrite those values for any user. The altered information is reflected in payroll export reports, effectively enabling covert manipulation of financial compensation data and undermining confidentiality and integrity of payroll records.

Affected Systems

The vulnerability affects all Dolibarr installations running a version older than 24.0.0. It is tied to the Dolibarr core product and targets the REST API used for user updates.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity level. Although an EPSS score is not available and the flaw is not listed in CISA’s KEV catalog, the flaw requires only authenticated API access with user‑write privileges, a condition common in many business deployments. The lack of a public exploit does not reduce the likelihood that an attacker could craft a custom payload; the flaw is trivially exploitable through the documented API endpoint.

Generated by OpenCVE AI on August 24, 2026 at 20:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dolibarr to version 24.0.0 or later to eliminate the authentication flaw.
  • Revoke unnecessary user‑write permissions for API users, limiting write access to only those who require it for legitimate maintenance.
  • Perform a payroll data audit to identify any unauthorized changes made prior to applying the patch.

Generated by OpenCVE AI on August 24, 2026 at 20:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Dolibarr
Dolibarr dolibarr
Vendors & Products Dolibarr
Dolibarr dolibarr

Mon, 24 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Description Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update endpoint that allows attackers with user-write rights to modify payroll fields by exploiting an incomplete credential denylist that omits payroll columns. Attackers can rewrite salary, bonus, hourly rate, daily rate, and weekly hours for any user without holding payroll rights, with the modified values appearing in payroll export reports.
Title Dolibarr < 24.0.0 REST API Improper Authorization via User Update Endpoint
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Dolibarr Dolibarr
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-29T11:47:38.779Z

Reserved: 2026-08-06T20:42:17.834Z

Link: CVE-2026-71508

cve-icon Vulnrichment

Updated: 2026-08-24T19:19:30.135Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T19:16:50.253

Modified: 2026-09-08T20:23:49.880

Link: CVE-2026-71508

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:00:13Z

Weaknesses