๐Ÿ” CVE Alert

CVE-2026-78160

MEDIUM 6.3

Dolibarr ERP User Notes note.php authorization

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability has been found in Dolibarr ERP up to 18.0.10/22.0.5/23.0.3. This issue affects some unknown processing of the file /user/note.php of the component User Notes Handler. The manipulation of the argument ID leads to authorization bypass. The attack can be initiated remotely. Upgrading to version 23.0.4 and 24.0.0 is capable of addressing this issue. The identifier of the patch is 9b5229ef3a9b58d00252d327936b022fb739f149. Upgrading the affected component is advised.

CWE CWE-639 CWE-285
Vendor dolibarr
Product erp
Published Aug 24, 2026
Stay Ahead of the Next One

Get instant alerts for dolibarr erp

Be the first to know when new medium vulnerabilities affecting dolibarr erp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Dolibarr / ERP
18.0.0 18.0.1 18.0.2 18.0.3 18.0.4 18.0.5 18.0.6 18.0.7 18.0.8 18.0.9 18.0.10 22.0.0 22.0.1 22.0.2 22.0.3 22.0.4 22.0.5 23.0.0 23.0.1 23.0.2 23.0.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/394542 vuldb.com: https://vuldb.com/vuln/394542/cti vuldb.com: https://vuldb.com/cve/CVE-2026-78160 vuldb.com: https://vuldb.com/submit/883067 github.com: https://github.com/Dolibarr/dolibarr/issues/39063 github.com: https://github.com/Dolibarr/dolibarr/pull/39123 github.com: https://github.com/Dolibarr/dolibarr/commit/9b5229ef3a9b58d00252d327936b022fb739f149 github.com: https://github.com/Dolibarr/dolibarr/releases/tag/23.0.4

Credits

๐Ÿ” Abderrahmane Aksoum (VulDB User)