CVE-2026-73692
Authorization Bypass via Inverted Boolean in clonetasks Mass Action in Dolibarr ERP/CRM
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
Dolibarr contains an authorization bypass vulnerability in the clonetasks mass action that allows authenticated users with project creation permissions to clone tasks into private projects they are not authorized to access. An inverted boolean condition in the private-project membership check within actions_massactions.inc.php causes the authorization flag to be set for unauthorized users, allowing attackers to supply a user-controlled projectid POST parameter to create task records in any private project.
| Vendor | dolibarr |
| Product | dolibarr erp/crm |
| Published | Aug 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for dolibarr dolibarr erp/crm
Be the first to know when new medium vulnerabilities affecting dolibarr dolibarr erp/crm are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup