Junglewise Threat Intelligence

CVE-2026-71507: Dolibarr broken object-level authorization in REST API bank account routes

CVE-2026-71507 · Severity: medium · CVSS 6.5 · Published 2026-08-24

Technologies: Dolibarr. Vendors: Dolibarr.

Executive brief

Dolibarr is an open-source business management suite used for invoicing, accounting, and supplier payment processing. A vulnerability in its REST API allows authenticated users with limited permissions to modify bank account details for any company, including injecting fraudulent payment routing information. Attackers can redirect outgoing payments meant for legitimate suppliers to attacker-controlled accounts.

Technical details

The vulnerability is a broken object-level authorization (BOLA) flaw in the REST API routes that handle company bank account write operations. Authenticated attackers with third-party creation rights can bypass authorization checks to create, replace, or delete bank account records for any company in the system without requiring read access to that company. The exploit involves injecting attacker-controlled IBAN numbers into company records, which are then embedded in regenerated SEPA credit-transfer files used for automated payment processing. The vulnerability was fixed in version 24.0.0 as documented in GitHub commit c100564.

Affected products

  • Dolibarr Dolibarr before 24.0.0

Timeline

  • 2026-08-24: disclosed

References

Related threats