Description
A weakness has been identified in Dolibarr up to 21.0.4/22.0.5/23.0.3. Affected by this issue is some unknown functionality of the file htdocs/core/filemanagerdol/connectors/php/config.inc.php of the component Legacy File Manager. Executing a manipulation can lead to improper access controls. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 23.0.4 can resolve this issue. This patch is called ef6631e9bd5ec4b8cec0e88f1796d3d10dad02ec. It is suggested to upgrade the affected component.
Published: 2026-09-04
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in Dolibarr’s Legacy File Manager component, specifically the configuration file located at htdocs/core/filemanagerdol/connectors/php/config.inc.php. Manipulation of this file can lead to improper access controls, allowing attackers to bypass intended restrictions. The flaw may be exploited remotely, and publicly available exploits have been released, indicating that the vulnerability could be used for attacks.

Affected Systems

Affected systems include Dolibarr installations running any of the following versions: 21.0.4, 22.0.5, and 23.0.3. Upgrading to version 23.0.4 or later incorporates a patch (commit ef6631e9bd5ec4b8cec0e88f1796d3d10dad02ec) that resolves the issue.

Risk and Exploitability

The CVSS score of 5.3 reflects moderate severity. EPSS is not available, but the existence of public exploits suggests that the vulnerability could be used in practice. The flaw can be triggered remotely and is not listed in the CISA KEV catalogue. Attackers may exploit the improper access controls to read or modify files that should be protected, potentially compromising confidentiality and integrity.

Generated by OpenCVE AI on September 4, 2026 at 04:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dolibarr to version 23.0.4 or later, incorporating the patch from commit ef6631e9bd5ec4b8cec0e88f1796d3d10dad02ec.
  • If the legacy file manager component is not required, remove or disable it to reduce the attack surface.
  • After applying the fix, review file permissions and audit logs for any abnormal access patterns that could indicate exploitation attempts.

Generated by OpenCVE AI on September 4, 2026 at 04:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in Dolibarr up to 21.0.4/22.0.5/23.0.3. Affected by this issue is some unknown functionality of the file htdocs/core/filemanagerdol/connectors/php/config.inc.php of the component Legacy File Manager. Executing a manipulation can lead to improper access controls. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 23.0.4 can resolve this issue. This patch is called ef6631e9bd5ec4b8cec0e88f1796d3d10dad02ec. It is suggested to upgrade the affected component.
Title Dolibarr Legacy File Manager config.inc.php access control
First Time appeared Dolibarr
Dolibarr dolibarr
Weaknesses CWE-266
CWE-284
CPEs cpe:2.3:a:dolibarr:dolibarr:*:*:*:*:*:*:*:*
Vendors & Products Dolibarr
Dolibarr dolibarr
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Dolibarr Dolibarr
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-04T02:45:11.085Z

Reserved: 2026-09-03T18:25:32.291Z

Link: CVE-2026-85401

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-04T03:17:46.677

Modified: 2026-09-04T03:17:46.677

Link: CVE-2026-85401

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T05:30:13Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-284

    Improper Access Control