Executive brief
Dolibarr is an open-source ERP and CRM system used to manage business operations, projects, and contacts. This vulnerability allows authenticated users with project creation permissions to clone tasks into private projects they shouldn't have access to, due to an inverted authorization check. An attacker could exploit this to move sensitive project work into unauthorized private projects, exposing task information and disrupting project management workflows.
Technical details
The vulnerability is an authorization bypass caused by an inverted boolean condition in the clonetasks mass action handler (htdocs/core/actions_massactions.inc.php, line 1949). The code uses !in_array() to check whether an authenticated user is authorized for a private target project; inverting this logic allows users without access to bypass the check. Exploitation requires an authenticated user account with project creation permissions, but no access to the target private project. When cloning tasks via the mass action handler, the attacker can clone tasks into unauthorized private projects. The fix is available in version 24.0.0 (released 2026-08-20), which corrects the inverted condition to in_array().
Affected products
- Dolibarr Dolibarr 21.0.0 before 24.0.0
Timeline
- 2026-08-24: disclosed
- 2026-08-20: patched: Fix released in version 24.0.0