CVE-2026-107706: Dolibarr before 24.0.2 Incorrect Authorization via updateextrafield.php
Dolibarr ERP CRM before 24.0.2 contains an incorrect authorization vulnerability in htdocs/core/ajax/updateextrafield.php that checks only read permission before writing extrafield values. Authenticated users with read-only access can POST objectType, objectId, field and value parameters to persistently modify extrafields on viewable third parties, products, members, projects or contacts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dolibarr ERP CRMto a version that resolves this vulnerability.Fixed in 24.0.2
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated Dolibarr user who has read-only access to a viewable third party, product, member, project, or contact can exploit it. The user does not need write permission for the affected object.
What does exploitation require?
The attacker must be able to authenticate and send a POST request to updateextrafield.php with objectType, objectId, field, and value parameters. Exploitation is network-accessible and requires no user interaction.
What data can be modified?
The vulnerability allows persistent modification of extrafield values on objects the attacker can view, including third parties, products, members, projects, and contacts. The provided information does not indicate modification of standard non-extrafield properties.
Which versions are affected?
Dolibarr ERP CRM versions before 24.0.2 are affected. Updating to 24.0.2 or later addresses the identified authorization flaw.