CVE-2026-78160
Dolibarr ERP User Notes note.php authorization
CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability has been found in Dolibarr ERP up to 18.0.10/22.0.5/23.0.3. This issue affects some unknown processing of the file /user/note.php of the component User Notes Handler. The manipulation of the argument ID leads to authorization bypass. The attack can be initiated remotely. Upgrading to version 23.0.4 and 24.0.0 is capable of addressing this issue. The identifier of the patch is 9b5229ef3a9b58d00252d327936b022fb739f149. Upgrading the affected component is advised.
| CWE | CWE-639 CWE-285 |
| Vendor | dolibarr |
| Product | erp |
| Published | Aug 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for dolibarr erp
Be the first to know when new medium vulnerabilities affecting dolibarr erp are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Dolibarr / ERP
18.0.0 18.0.1 18.0.2 18.0.3 18.0.4 18.0.5 18.0.6 18.0.7 18.0.8 18.0.9 18.0.10 22.0.0 22.0.1 22.0.2 22.0.3 22.0.4 22.0.5 23.0.0 23.0.1 23.0.2 23.0.3
References
vuldb.com: https://vuldb.com/vuln/394542 vuldb.com: https://vuldb.com/vuln/394542/cti vuldb.com: https://vuldb.com/cve/CVE-2026-78160 vuldb.com: https://vuldb.com/submit/883067 github.com: https://github.com/Dolibarr/dolibarr/issues/39063 github.com: https://github.com/Dolibarr/dolibarr/pull/39123 github.com: https://github.com/Dolibarr/dolibarr/commit/9b5229ef3a9b58d00252d327936b022fb739f149 github.com: https://github.com/Dolibarr/dolibarr/releases/tag/23.0.4
Credits
๐ Abderrahmane Aksoum (VulDB User)