Junglewise Threat Intelligence

CVE-2026-71510: Dolibarr SQL injection in users REST API

CVE-2026-71510 · Severity: medium · CVSS 6.5 · Published 2026-08-24

Technologies: Dolibarr. Vendors: Dolibarr.

Executive brief

Dolibarr is an open-source ERP and CRM system used to manage business operations, including payroll and personnel data. A SQL injection vulnerability in the users REST API allows authenticated users with basic read permissions to extract sensitive information such as employee salaries and password hashes that are normally hidden from standard API responses. An attacker with these credentials could enumerate database columns and systematically recover confidential data through search-based techniques.

Technical details

The vulnerability is a SQL injection flaw in the users REST API endpoint where filter parameters are not properly sanitized before being incorporated into SQL WHERE clauses. Attackers with user-read privileges can exploit this by crafting malicious filter parameters to extract restricted data. The attack leverages binary search on numeric fields (e.g., salary) and LIKE prefix iteration on string fields (e.g., password verifiers), combined with raw database error messages that leak column names. Authentication is required (user-read right), but the attack is network-accessible via the REST API. Patches are available in Dolibarr 24.0.0 and later via commit 12687f83705c2a1e46aaf6f8d1ac7347bee4710c.

Affected products

  • Dolibarr Dolibarr before 24.0.0

Timeline

  • 2026-08-24: disclosed

References

Related threats