CVE-2026-19350
Dolibarr ERP TakePOS invoice.php fail authorization
CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component TakePOS Module. Such manipulation leads to missing authorization. The attack may be performed from remote. The name of the patch is 8992ce8704da947b6abe7b65a6fe59aed736bb81. It is advisable to implement a patch to correct this issue.
| CWE | CWE-862 CWE-863 |
| Vendor | dolibarr |
| Product | erp |
| Published | Aug 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for dolibarr erp
Be the first to know when new medium vulnerabilities affecting dolibarr erp are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Dolibarr / ERP
23.0.0 23.0.1 23.0.2 23.0.3
References
vuldb.com: https://vuldb.com/vuln/387189 vuldb.com: https://vuldb.com/vuln/387189/cti vuldb.com: https://vuldb.com/cve/CVE-2026-19350 vuldb.com: https://vuldb.com/submit/865736 github.com: https://github.com/Dolibarr/dolibarr/issues/38949 github.com: https://github.com/Dolibarr/dolibarr/pull/38999 github.com: https://github.com/Dolibarr/dolibarr/commit/8992ce8704da947b6abe7b65a6fe59aed736bb81
Credits
๐ Abderrahmane Aksoum (VulDB User)