Description
Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive denylist bypass vulnerability in the sqlfilters API query parameter that allows authenticated attackers to recover protected database fields by supplying uppercase variants of denylist-protected field names. Attackers can exploit the case-insensitive database column resolution against the case-sensitive denylist check in the core library to use prefix-matching predicates as a boolean oracle and extract full password hashes for any user account, including administrators.
Published: 2026-09-11
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Retrieval of Sensitive Data Including Password Hashes
Action: Patch Now
AI Analysis

Impact

Dolibarr 24.0.0 contains a case‑sensitive denylist bypass in the sqlfilters API query parameter. An authenticated attacker can supply uppercase variants of denylist‑protected field names, causing the denylist check to fail while the database resolver remains case‑insensitive. This allows the attacker to recover protected database fields, including full password hashes for any user, even administrators.

Affected Systems

All Dolibarr instances running version 24.0.0 or earlier, not including 24.0.1 and later releases, are vulnerable to this bypass. The feature is triggered through the exposed sqlfilters API, so only systems with the API enabled are impacted.

Risk and Exploitability

The reported CVSS score of 7.1 reflects a high severity that compromises confidentiality. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no confirmed public exploits yet. Exploitation requires valid authentication to the server; the attacker would craft an API request containing an uppercase protectively lookup field, rely on the mismatch between the case‑insensitive database resolution and the case‑sensitive denylist, and obtain password hashes. The presence of a generic authenticated API means that users with any valid credentials can attempt the attack without additional permissions.

Generated by OpenCVE AI on September 11, 2026 at 17:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Dolibarr 24.0.1 or later update that removes the case‑sensitive denylist bypass.
  • If an upgrade is not yet possible, restrict access to the sqlfilters API by locking it behind app‑layer access controls or disabling it for non‑admin roles.
  • Ensure all user accounts use secure, salted hashing algorithms and monitor authentication logs for anomalous activity.

Generated by OpenCVE AI on September 11, 2026 at 17:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Dolibarr dolibarr Erp\/crm
CPEs cpe:2.3:a:dolibarr:dolibarr_erp\/crm:*:*:*:*:*:*:*:*
Vendors & Products Dolibarr dolibarr Erp\/crm

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Dolibarr
Dolibarr dolibarr
Vendors & Products Dolibarr
Dolibarr dolibarr
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive denylist bypass vulnerability in the sqlfilters API query parameter that allows authenticated attackers to recover protected database fields by supplying uppercase variants of denylist-protected field names. Attackers can exploit the case-insensitive database column resolution against the case-sensitive denylist check in the core library to use prefix-matching predicates as a boolean oracle and extract full password hashes for any user account, including administrators.
Title Dolibarr 24.0.0 < 24.0.1 SQL Filter Denylist Bypass via sqlfilters Parameter
Weaknesses CWE-178
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Dolibarr Dolibarr Dolibarr Erp\/crm
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T15:21:47.690Z

Reserved: 2026-09-10T16:23:54.470Z

Link: CVE-2026-89012

cve-icon Vulnrichment

Updated: 2026-09-11T19:16:51.415Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T16:17:48.680

Modified: 2026-09-23T17:17:46.343

Link: CVE-2026-89012

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T21:15:02Z

Weaknesses
  • CWE-178

    Improper Handling of Case Sensitivity