Description
Dolibarr 23.0.4 before 24.0.1 contains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files through the document storage endpoints by supplying a crafted hashp parameter value. Attackers can send a request with hashp=shared to skip token validation while satisfying the authorization condition in htdocs/document.php and htdocs/viewimage.php, gaining access to application logs, uploaded business documents, database backups containing password hashes, and files belonging to other multicompany entities.
Published: 2026-09-11
Score: 8.7 High
EPSS: 1.6% Low
KEV: No
Impact: Unauthorized file read via authorization bypass.
Action: Patch Now
AI Analysis

Impact

An unauthenticated attacker can supply a specially crafted hashp parameter value in the document.php and viewimage.php endpoints to bypass token verification while still meeting authorization checks. This allows the attacker to download arbitrary files from the document storage, including application logs, business documents, database backups that may contain password hashes, and files belonging to other multicompany entities. The weakness is an Authorization Bypass (CWE‑863). It is inferred from the description that the vulnerability can be triggered by a simple unauthenticated HTTP request.

Affected Systems

The vulnerability affects Dolibarr installations running any 23.x release from 23.0.4 up to but not including 24.0.1. Deployments that expose the document.php or viewimage.php endpoints over the web without additional protection are susceptible, regardless of the multicompany configuration.

Risk and Exploitability

The flaw has a CVSS score of 8.7, indicating high impact. The EPSS score of 2% suggests a low but non‑zero probability of exploitation; nevertheless, because the vulnerability can be triggered with a simple unauthenticated HTTP request containing a crafted hashp parameter, it remains a significant risk to deployments exposing document.php or viewimage.php. Although it is not listed in the CISA KEV catalog, its high CVSS score and the lack of authentication requirements make it a priority for close monitoring and immediate remediation.

Generated by OpenCVE AI on September 29, 2026 at 15:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Dolibarr to version 24.0.1 or later to apply the vendor‑provided fix.
  • If an upgrade cannot be performed immediately, limit access to the document.php and viewimage.php endpoints to authenticated users or block the hashp parameter through web‑server rules to prevent the bypass.
  • Move application logs, database backups, and other sensitive files outside of the document storage directory and enforce strict file permissions to mitigate accidental exposure.

Generated by OpenCVE AI on September 29, 2026 at 15:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Dolibarr dolibarr Erp\/crm
CPEs cpe:2.3:a:dolibarr:dolibarr_erp\/crm:*:*:*:*:*:*:*:*
Vendors & Products Dolibarr dolibarr Erp\/crm

Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description Dolibarr 23.0.4 before 24.0.1 ontains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files through the document storage endpoints by supplying a crafted hashp parameter value. Attackers can send a request with hashp=shared to skip token validation while satisfying the authorization condition in htdocs/document.php and htdocs/viewimage.php, gaining access to application logs, uploaded business documents, database backups containing password hashes, and files belonging to other multicompany entities. Dolibarr 23.0.4 before 24.0.1 contains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files through the document storage endpoints by supplying a crafted hashp parameter value. Attackers can send a request with hashp=shared to skip token validation while satisfying the authorization condition in htdocs/document.php and htdocs/viewimage.php, gaining access to application logs, uploaded business documents, database backups containing password hashes, and files belonging to other multicompany entities.

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Dolibarr
Dolibarr dolibarr
Vendors & Products Dolibarr
Dolibarr dolibarr

Fri, 11 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description Dolibarr 23.0.4 before 24.0.1 ontains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files through the document storage endpoints by supplying a crafted hashp parameter value. Attackers can send a request with hashp=shared to skip token validation while satisfying the authorization condition in htdocs/document.php and htdocs/viewimage.php, gaining access to application logs, uploaded business documents, database backups containing password hashes, and files belonging to other multicompany entities.
Title Dolibarr 23.0.4 < 24.0.1 Authorization Bypass via hashp Parameter in document.php
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Dolibarr Dolibarr Dolibarr Erp\/crm
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T15:21:48.318Z

Reserved: 2026-09-10T16:23:54.471Z

Link: CVE-2026-89013

cve-icon Vulnrichment

Updated: 2026-09-11T18:06:36.333Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T16:17:48.853

Modified: 2026-09-23T17:17:46.367

Link: CVE-2026-89013

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T16:00:16Z

Weaknesses