Executive brief
Dolibarr ERP/CRM, a popular open-source suite for managing business operations, contains a critical security flaw that allows remote attackers to execute unauthorized code on the server. By sending a specially crafted request to a specific internal component, an attacker can take full control of the application and the underlying server. This could lead to the theft of sensitive business data, complete service disruption, or the installation of ransomware.
Technical details
The vulnerability is a PHP code injection (CWE-94) located in 'htdocs/core/actions_addupdatedelete.inc.php'. The root cause is the unsafe use of the 'dol_eval()' function, which acts as a wrapper for PHP's native 'eval()'. The application fails to properly sanitize or validate input before passing it to this function at approximately 31 different call sites. An attacker can exploit this by providing a malicious PHP payload via HTTP parameters that are processed by this include file, which is used by over 120 different files across the application. This allows for arbitrary code execution with the privileges of the web server user. The issue stems from a long-standing architectural reliance on a function blacklist that has proven insufficient to prevent injection.
Affected products
- Dolibarr Dolibarr ERP/CRM 22.0.0 - 22.0.4, 24.0.0-alpha
Timeline
- 2026-04-10: other: CVE assigned by MITRE
- 2026-05-25: disclosed: Full technical disclosure by researcher Bryam Vargas
- 2026-05-27: advisory: NVD publication date