Junglewise Threat Intelligence

CVE-2026-89012: Dolibarr case-sensitive denylist bypass in sqlfilters API

CVE-2026-89012 · Severity: medium · CVSS 6.5 · Published 2026-09-11

Technologies: Dolibarr. Vendors: Dolibarr.

Executive brief

Dolibarr is an open-source business management suite used for customer relations, invoicing, and accounting. This vulnerability allows authenticated users to bypass field-level access restrictions by using uppercase field names in API queries, enabling them to extract sensitive database information including password hashes for any user account, including administrators.

Technical details

The sqlfilters API parameter in Dolibarr 24.0.0 performs a case-sensitive denylist check against forbidden database field names, but the underlying database column resolution is case-insensitive, creating a bypass. An authenticated attacker can submit uppercase or mixed-case variants of protected field names (e.g., PASSWORD instead of password) to circumvent the denylist. By exploiting prefix-matching predicates as a boolean oracle, attackers can extract full password hashes for any user account. The vulnerability exists in htdocs/core/lib/functions.lib.php in the dolForgeSQLCriteriaCallback() function. The fix applies case-insensitive comparison to the denylist check by wrapping the operand in strtolower() before comparison.

Affected products

  • Dolibarr Dolibarr 24.0.0 before 24.0.1

Timeline

  • 2026-09-11: disclosed
  • 2026-09-07: patched: Fix released in version 24.0.1

References

Related threats