CVE-2026-71505

Source
https://cve.org/CVERecord?id=CVE-2026-71505
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-71505.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-71505
Published
2026-08-24T19:00:47.470Z
Modified
2026-08-30T03:30:40.441141785Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Dolibarr < 24.0.0 REST API Broken Object-Level Authorization via Third-Party Write Route
Details

Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site account write routes that allows authenticated attackers with third-party creation rights to overwrite the WebPortal password of any company by bypassing per-object access checks that are only enforced on read routes. Attackers can replace the victim company's WebPortal password through the write endpoint, authenticate as that company to access its invoice data, and also obtain the victim's previous password verifier from the API response.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71505.json",
    "cwe_ids": [
        "CWE-639"
    ],
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/dolibarr/dolibarr

Affected ranges

Type
GIT
Repo
https://github.com/dolibarr/dolibarr
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "24.0.0"
        }
    ]
}

Affected versions

14.*
14.0.0
14.0.1
3.*
3.3.beta1_20121221
3.4.beta1_20130429
3.4.beta1_20130502
3.5.beta1_20131106
3.5.beta1_20131120
3.6.0
3.6.0-alpha
3.6.0-beta
3.6.1
3.6.2
3.6.beta1_20140514
3.7.0
3.7.1
3.8.0-beta
4.*
4.0.0-rc
5.*
5.0.0-beta
6.*
6.0.0-beta
Other
lne_audit_init_20260601

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-71505.json"