Junglewise Threat Intelligence

CVE-2026-78160: Dolibarr ERP authorization bypass in user notes

CVE-2026-78160 · Severity: medium · CVSS 6.3 · Published 2026-08-24

Technologies: Dolibarr ERP. Vendors: Dolibarr.

Executive brief

Dolibarr ERP is a business management system used to manage accounting, inventory, and user accounts. A user with only permission to edit their own profile can exploit an access control flaw to modify notes for any other user, including administrators. This could allow attackers to tamper with sensitive administrative information and inject false data into system records.

Technical details

The vulnerability is a broken access control (IDOR) flaw in the User Notes Handler component, specifically in /user/note.php. When a user modifies notes for a profile, the application fails to verify that the 'id' parameter matches the currently authenticated user, instead only checking superficial permissions. An attacker with "Create/modify his own user information" permission can manipulate the ID parameter to edit notes belonging to any user, including superadministrators. The attack is remotely exploitable and requires only a valid user account. A patch was applied in commit 9b5229ef3a9b58d00252d327936b022fb739f149 to enforce proper authorization checks on the ID parameter.

Affected products

  • Dolibarr ERP up to 18.0.10, 22.0.5, 23.0.3

Timeline

  • 2026-08-24: disclosed
  • 2026-08-24: patched: Fixed in versions 23.0.4 and 24.0.0 via commit 9b5229ef3a9b58d00252d327936b022fb739f149

References