CVE-2026-10154: Dolibarr ERP CRM messaging.php authorization
A vulnerability has been found in Dolibarr ERP CRM 23.0.0/23.0.1/23.0.2. The affected element is an unknown function of the file htdocs/user/messaging.php. Such manipulation of the argument ID leads to authorization bypass. The attack can be executed remotely. Upgrading to version 23.0.3 is sufficient to fix this issue. The name of the patch is 119b3606c7a701747a57a1f18b1a9e7666f678e2. It is suggested to upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dolibarr ERP CRMto a version that resolves this vulnerability.Fixed in 23.0.3Patch 119b3606c7a701747a57a1f18b1a9e7666f678e2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10154?
The severity of CVE-2026-10154 is medium with a score of 4.3.
How do I fix CVE-2026-10154?
To fix CVE-2026-10154, you should upgrade to Dolibarr ERP CRM version 23.0.3 or later.
What does CVE-2026-10154 impact?
CVE-2026-10154 impacts the messaging.php component of Dolibarr ERP CRM.
Can CVE-2026-10154 be exploited remotely?
Yes, CVE-2026-10154 can be exploited remotely due to the authorization bypass vulnerability.
Which versions of Dolibarr ERP CRM are affected by CVE-2026-10154?
The affected versions of Dolibarr ERP CRM are 23.0.0, 23.0.1, and 23.0.2.