CVE-2026-37712: Code Injection
Published May 27, 2026
·Updated
An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/cron/class/cronjob.class.php, calluserfuncarray() in function job type
Affected Software
1 affected component
dolibarr Dolibarr ERP/CRM>=22.0.0<=22.0.4, =24.0.0-alpha
Event History
May 27, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-37712?
The severity of CVE-2026-37712 is high with a CVSS score of 7.3.
2
What kind of vulnerability is CVE-2026-37712?
CVE-2026-37712 is a code injection vulnerability affecting Dolibarr ERP/CRM.
3
How do I fix CVE-2026-37712?
To fix CVE-2026-37712, upgrade to Dolibarr ERP/CRM version 22.0.5 or later.
4
What versions of Dolibarr are affected by CVE-2026-37712?
CVE-2026-37712 affects Dolibarr ERP/CRM versions 22.0.0 through 22.0.4 and 24.0.0-alpha.
5
Can CVE-2026-37712 allow remote code execution?
Yes, CVE-2026-37712 allows a remote attacker to execute arbitrary code.