Executive brief
Dolibarr is an open-source business management system used by organizations to manage customer relationships, invoicing, and operations. A flaw in the Members REST API allows users with basic member-creation privileges to reset passwords for any account, including administrators, effectively taking over those accounts and locking out legitimate users. This could give attackers full control of the system and access to all business data.
Technical details
The vulnerability is an improper authorization / mass assignment flaw in the Members REST API (htdocs/adherents/class/api_members.class.php) in Dolibarr before version 24.0.0. An attacker with member-creation rights can supply an arbitrary user account identifier and new password in the request body to overwrite credentials without verification of change-password permissions. The vulnerability allows privilege escalation by targeting administrator accounts, and no user interaction or elevated privileges beyond member creation are required. The issue was fixed in commit fbf476c by restricting sensitive fields in the API's create/update operations.
Affected products
- Dolibarr Dolibarr before 24.0.0
Timeline
- 2026-08-24: disclosed