CVE-2026-71507
Dolibarr < 24.0.0 REST API Broken Object-Level Authorization via Bank Account Routes
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account write routes that allows authenticated attackers with third-party creation rights to create, replace, or delete bank account details of any company without requiring read access to that company. Attackers can inject attacker-controlled IBANs as creditor accounts, which are then written into regenerated SEPA credit-transfer files, redirecting outgoing payments to attacker-controlled accounts.
| CWE | CWE-639 |
| Vendor | dolibarr |
| Product | dolibarr |
| Published | Aug 24, 2026 |
| Last Updated | Aug 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for dolibarr dolibarr
Be the first to know when new medium vulnerabilities affecting dolibarr dolibarr are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Affected Versions
Dolibarr / dolibarr
0 < 24.0.0
References
codeant.ai: https://codeant.ai/security-research/cve-2026-71507-dolibarr-bola-lets-attackers-redirect-supplier-payments github.com: https://github.com/Dolibarr/dolibarr/releases/tag/24.0.0 github.com: https://github.com/Dolibarr/dolibarr/commit/c100564d059e19c711317c734d302a90b11e2e8b vulncheck.com: https://www.vulncheck.com/advisories/dolibarr-rest-api-broken-object-level-authorization-via-bank-account-routes
Credits
CodeAnt AI Security Research VulnCheck