CVE-2026-37711: Code Injection
Published May 27, 2026
·Updated
An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/core/actionsaddupdatedelete.inc.php
Affected Software
1 affected component
dolibarr Dolibarr ERP/CRM>=22.0.0<=22.0.4, =24.0.0-alpha
Event History
May 27, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-37711?
CVE-2026-37711 has a high severity score of 7.3 on the CVSS scale.
2
How do I fix CVE-2026-37711?
To mitigate CVE-2026-37711, users should update Dolibarr ERP/CRM to versions beyond 22.0.4 and 24.0.0-alpha.
3
What type of vulnerability is CVS-2026-37711?
CVE-2026-37711 is classified as a code injection vulnerability.
4
What versions of Dolibarr are affected by CVE-2026-37711?
CVE-2026-37711 affects Dolibarr ERP/CRM versions 22.0.0 through 22.0.4 and version 24.0.0-alpha.
5
Can CVE-2026-37711 be exploited remotely?
Yes, CVE-2026-37711 allows remote attackers to execute arbitrary code.