Executive brief
Dolibarr ERP/CRM is an open-source software suite used by businesses to manage operations like inventory, sales, and projects. A critical security flaw in the system's task scheduler allows remote attackers to execute unauthorized commands on the underlying server. This could lead to a complete system takeover, theft of sensitive business data, or a total disruption of company operations.
Technical details
The vulnerability is classified as OS Command Injection (CWE-78) and Arbitrary Code Execution. It resides in 'htdocs/cron/class/cronjob.class.php' where the 'call_user_func_array()' PHP function is used to execute scheduled jobs without sufficient restriction on the function name or arguments. An attacker can leverage this to call dangerous system functions (like 'exec' or 'system') to execute arbitrary OS commands. While Dolibarr often employs a blacklist-based security model via 'dol_eval()', this specific vector bypasses those filters by directly reaching a PHP callback sink. The vulnerability is reachable by remote attackers and can be chained with other 'dol_eval()' bypasses to achieve full system compromise.
Affected products
- Dolibarr ERP/CRM 22.0.0 - 22.0.4, 24.0.0-alpha
Timeline
- 2026-04-10: other: CVE assigned by MITRE
- 2026-05-25: disclosed: Full technical write-up published by researcher bryamzxz
- 2026-05-27: advisory: NVD publication date