CVE-2026-19930: Dolibarr User Cloning card.php ldap injection
A security flaw has been discovered in Dolibarr up to 23.0.3. Affected is an unknown function of the file htdocs/user/card.php of the component User Cloning. The manipulation of the argument ID results in ldap injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The patch is identified as 798e65356ede03c2812ab1a728f23fae34de5592. It is advisable to implement a patch to correct this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch 798e65356ede03c2812ab1a728f23fae34de5592 - Compensating control
Apply compensating controls to reduce exposure by blocking or restricting remote access to Dolibarr instance endpoints that process requests to htdocs/user/card.php (User Cloning) until the patch is applied.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19930?
The severity of CVE-2026-19930 is rated as medium with a score of 6.3.
How do I fix CVE-2026-19930?
To fix CVE-2026-19930, update Dolibarr to a version later than 23.0.3 that addresses this LDAP injection vulnerability.
What component of Dolibarr is affected by CVE-2026-19930?
CVE-2026-19930 affects the User Cloning functionality in the htdocs/user/card.php file.
Can CVE-2026-19930 be exploited remotely?
Yes, CVE-2026-19930 allows for remote exploitation due to the nature of the LDAP injection.
What type of attack is CVE-2026-19930 associated with?
CVE-2026-19930 is associated with LDAP injection attacks that can occur through manipulation of the argument ID.