CVE-2026-71508
Dolibarr < 24.0.0 REST API Improper Authorization via User Update Endpoint
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update endpoint that allows attackers with user-write rights to modify payroll fields by exploiting an incomplete credential denylist that omits payroll columns. Attackers can rewrite salary, bonus, hourly rate, daily rate, and weekly hours for any user without holding payroll rights, with the modified values appearing in payroll export reports.
| CWE | CWE-862 |
| Vendor | dolibarr |
| Product | dolibarr |
| Published | Aug 24, 2026 |
| Last Updated | Aug 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for dolibarr dolibarr
Be the first to know when new medium vulnerabilities affecting dolibarr dolibarr are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Affected Versions
Dolibarr / dolibarr
0 < 24.0.0
References
codeant.ai: https://codeant.ai/security-research/cve-2026-71508-dolibarr-payroll-mass-assignment github.com: https://github.com/Dolibarr/dolibarr/releases/tag/24.0.0 github.com: https://github.com/Dolibarr/dolibarr/commit/c85d0e840725a3c1a2f49b3e97766469c3cb02b6 vulncheck.com: https://www.vulncheck.com/advisories/dolibarr-rest-api-improper-authorization-via-user-update-endpoint
Credits
CodeAnt AI Security Research VulnCheck