๐Ÿ” CVE Alert

CVE-2026-71506

HIGH 8.1

Dolibarr < 24.0.0 Payments REST API Improper Authorization via Delete Endpoint

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that allows authenticated attackers with invoice-deletion rights to permanently delete any payment record by bypassing the intended payment-issuance rights check. Attackers can exploit this misconfigured permission check to zero paid amounts on invoices and remove entries from accounting exports, causing financial data integrity loss.

CWE CWE-863
Vendor dolibarr
Product dolibarr
Published Aug 24, 2026
Stay Ahead of the Next One

Get instant alerts for dolibarr dolibarr

Be the first to know when new high vulnerabilities affecting dolibarr dolibarr are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
High

Affected Versions

Dolibarr / dolibarr
0 < 24.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
codeant.ai: https://codeant.ai/security-research/cve-2026-71506-dolibarr-payment-deletion-via-incorrect-authorization github.com: https://github.com/Dolibarr/dolibarr/releases/tag/24.0.0 github.com: https://github.com/Dolibarr/dolibarr/commit/e01a12ffea4675f5bcc1c886f06ec6a29d5e4801 vulncheck.com: https://www.vulncheck.com/advisories/dolibarr-payments-rest-api-improper-authorization-via-delete-endpoint

Credits

CodeAnt AI Security Research VulnCheck