๐Ÿ” CVE Alert

CVE-2026-71504

HIGH 8.1

Dolibarr < 24.0.0 Members REST API Improper Authorization via Password Reset

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers with only member-creation rights to reset the password of any user account, including the system administrator, without verifying password-change permissions. Attackers can supply an arbitrary user account identifier and new password in the request body to overwrite credentials and immediately lock out the legitimate account holder.

CWE CWE-862 CWE-915
Vendor dolibarr
Product dolibarr
Published Aug 24, 2026
Last Updated Aug 24, 2026
Stay Ahead of the Next One

Get instant alerts for dolibarr dolibarr

Be the first to know when new high vulnerabilities affecting dolibarr dolibarr are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

Dolibarr / dolibarr
0 < 24.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
codeant.ai: https://codeant.ai/security-research/cve-2026-71504-mass-assignment-in-members-api-via-pass github.com: https://github.com/Dolibarr/dolibarr/releases/tag/24.0.0 github.com: https://github.com/Dolibarr/dolibarr/commit/fbf476cc5d9a21b16bfa04ab17d4e84eda38d7ce vulncheck.com: https://www.vulncheck.com/advisories/dolibarr-members-rest-api-improper-authorization-via-password-reset

Credits

CodeAnt AI Security Research VulnCheck