Junglewise Threat Intelligence

CVE-2026-10154: Dolibarr ERP CRM authorization bypass in messaging.php

CVE-2026-10154 · Severity: medium · CVSS 4.3 · Published 2026-05-31

Technologies: Dolibarr ERP CRM. Vendors: Dolibarr.

Executive brief

Dolibarr ERP CRM, an open-source suite used by businesses to manage customers and resources, contains a security flaw in its messaging component. An authenticated user can bypass normal authorization checks to view messages or data belonging to other users by manipulating identification numbers in web requests. This could lead to the unauthorized exposure of internal communications or sensitive user information.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in Dolibarr ERP CRM versions 23.0.0 through 23.0.2 within the `htdocs/user/messaging.php` file. The application fails to properly validate if the requesting user has the necessary permissions to access a specific record identified by the 'ID' parameter. A remote, authenticated attacker can exploit this by manipulating the ID argument to bypass authorization checks and view data belonging to other users. The issue is rooted in an improper implementation of the `restrictedArea` check and has been addressed in version 23.0.3 by adding explicit ownership and permission validation.

Affected products

  • Dolibarr Dolibarr ERP CRM 23.0.0, 23.0.1, 23.0.2

Timeline

  • 2026-05-31: disclosed
  • 2026-05-31: advisory
  • 2023-05-17: patched: Date of GitHub release 23.0.3

References

Related threats