Junglewise Threat Intelligence

CVE-2026-10215: Dolibarr ERP CRM improper authorization in Leave Request REST API

CVE-2026-10215 · Severity: medium · CVSS 4.3 · Published 2026-06-01

Technologies: Dolibarr ERP CRM, dolibarr/dolibarr (Packagist). Vendors: Dolibarr, Packagist.

Executive brief

Dolibarr ERP CRM, a popular open-source suite for managing business operations, contains a security flaw in its leave request system. A low-privileged employee can bypass normal security restrictions to view the private leave and holiday requests of other staff members. This could lead to the unauthorized exposure of sensitive employee scheduling and personal information.

Technical details

An improper authorization vulnerability exists in the Dolibarr ERP CRM Leave Request REST API. The flaw is located in the `checkUserAccessToObject` function within `htdocs/holiday/class/api_holidays.class.php`. While the web interface correctly enforces hierarchical access controls, the REST API fails to properly validate that a requesting user has the necessary permissions to view a specific holiday object. A remote, authenticated attacker with low-level privileges can exploit this to perform a horizontal unauthorized read of leave request data belonging to other users in the same entity. The issue is addressed in version 23.0.2.

Affected products

  • Dolibarr ERP CRM <= 23.0.1

Timeline

  • 2026-04-05: disclosed: Issue reported on GitHub
  • 2026-06-01: advisory: GHSA and CVE published
  • 2026-06-01: patched: Version 23.0.2 released

References

Related threats