CVE-2026-19350

Source
https://cve.org/CVERecord?id=CVE-2026-19350
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19350.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-19350
Downstream
Published
2026-08-09T10:45:10Z
Modified
2026-08-14T03:51:35Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X CVSS Calculator
Summary
Dolibarr ERP TakePOS invoice.php fail authorization
Details

A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component TakePOS Module. Such manipulation leads to missing authorization. The attack may be performed from remote. The name of the patch is 8992ce8704da947b6abe7b65a6fe59aed736bb81. It is advisable to implement a patch to correct this issue.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-862",
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19350.json"
}
References

Affected packages

Git / github.com/dolibarr/dolibarr

Affected ranges

Type
GIT
Repo
https://github.com/dolibarr/dolibarr
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "23.0.0"
        },
        {
            "last_affected": "23.0.0"
        },
        {
            "introduced": "23.0.1"
        },
        {
            "last_affected": "23.0.1"
        },
        {
            "introduced": "23.0.2"
        },
        {
            "last_affected": "23.0.2"
        },
        {
            "introduced": "23.0.3"
        },
        {
            "last_affected": "23.0.3"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

23.*
23.0.0
23.0.1
23.0.2
23.0.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19350.json"