CVE-2026-107706
Dolibarr before 24.0.2 Incorrect Authorization via updateextrafield.php
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
Dolibarr ERP CRM before 24.0.2 contains an incorrect authorization vulnerability in htdocs/core/ajax/updateextrafield.php that checks only read permission before writing extrafield values. Authenticated users with read-only access can POST objectType, objectId, field and value parameters to persistently modify extrafields on viewable third parties, products, members, projects or contacts.
| CWE | CWE-863 |
| Vendor | dolibarr |
| Product | dolibarr |
| Published | Oct 8, 2026 |
| Last Updated | Oct 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for dolibarr dolibarr
Be the first to know when new medium vulnerabilities affecting dolibarr dolibarr are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
Affected Versions
Dolibarr / dolibarr
0 < 24.0.2
References
github.com: https://github.com/Dolibarr/dolibarr/commit/3420d17b199059ac22fca8b59f23cb8962fc8ef8 github.com: https://github.com/Dolibarr/dolibarr github.com: https://github.com/Dolibarr/dolibarr/blob/24.0.1/htdocs/core/ajax/updateextrafield.php#L80 vulncheck.com: https://www.vulncheck.com/advisories/dolibarr-before-24.0.2-incorrect-authorization-via-updateextrafield-php
Credits
dexx-tech