CVE-2026-107706: Dolibarr before 24.0.2 Incorrect Authorization via updateextrafield.php

Published Oct 8, 2026
·
Updated

Dolibarr ERP CRM before 24.0.2 contains an incorrect authorization vulnerability in htdocs/core/ajax/updateextrafield.php that checks only read permission before writing extrafield values. Authenticated users with read-only access can POST objectType, objectId, field and value parameters to persistently modify extrafields on viewable third parties, products, members, projects or contacts.

Affected Software

1 affected component
dolibarr Dolibarr ERP CRM<24.0.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Dolibarr ERP CRM to a version that resolves this vulnerability.

    Fixed in 24.0.2

Event History

Oct 8, 2026
CVE Published
via MITRE·07:51 PM
Data Sourced
via MITRE·07:51 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Oct 9, 2026
Event
via NVD·12:04 PM

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated Dolibarr user who has read-only access to a viewable third party, product, member, project, or contact can exploit it. The user does not need write permission for the affected object.

2

What does exploitation require?

The attacker must be able to authenticate and send a POST request to updateextrafield.php with objectType, objectId, field, and value parameters. Exploitation is network-accessible and requires no user interaction.

3

What data can be modified?

The vulnerability allows persistent modification of extrafield values on objects the attacker can view, including third parties, products, members, projects, and contacts. The provided information does not indicate modification of standard non-extrafield properties.

4

Which versions are affected?

Dolibarr ERP CRM versions before 24.0.2 are affected. Updating to 24.0.2 or later addresses the identified authorization flaw.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203