๐Ÿ” CVE Alert

CVE-2026-89013

HIGH 7.5

Dolibarr 23.0.4 < 24.0.1 Authorization Bypass via hashp Parameter in document.php

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

Dolibarr 23.0.4 before 24.0.1 ontains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files through the document storage endpoints by supplying a crafted hashp parameter value. Attackers can send a request with hashp=shared to skip token validation while satisfying the authorization condition in htdocs/document.php and htdocs/viewimage.php, gaining access to application logs, uploaded business documents, database backups containing password hashes, and files belonging to other multicompany entities.

CWE CWE-863
Vendor dolibarr
Product dolibarr
Published Sep 11, 2026
Last Updated Sep 11, 2026
Stay Ahead of the Next One

Get instant alerts for dolibarr dolibarr

Be the first to know when new high vulnerabilities affecting dolibarr dolibarr are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

Dolibarr / Dolibarr
23.0.4 < 24.0.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Dolibarr/dolibarr/releases/tag/24.0.1 github.com: https://github.com/Dolibarr/dolibarr/commit/cd05688dbed8a4af6eef32faf4fc1e823a37bce9 vulncheck.com: https://www.vulncheck.com/advisories/dolibarr-authorization-bypass-via-hashp-parameter-in-document-php

Credits

Faceless