CVE-2026-37713: Code Injection
Published May 27, 2026
·Updated
An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/core/class/commonobject.class.php.
Affected Software
1 affected component
dolibarr Dolibarr ERP/CRM>=22.0.0<=22.0.4, =24.0.0-alpha
Event History
May 27, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-37713?
CVE-2026-37713 has a severity rating of high, with a CVSS score of 7.3.
2
How do I fix CVE-2026-37713?
To fix CVE-2026-37713, update Dolibarr ERP/CRM to version 22.0.5 or later, or to version 24.0.0-beta or later.
3
What version of Dolibarr ERP/CRM is affected by CVE-2026-37713?
CVE-2026-37713 affects Dolibarr ERP/CRM versions 22.0.0 through 22.0.4 and the 24.0.0-alpha version.
4
What type of vulnerability is CVE-2026-37713?
CVE-2026-37713 is classified as a code injection vulnerability.
5
Can CVE-2026-37713 be exploited remotely?
Yes, CVE-2026-37713 can be exploited by a remote attacker to execute arbitrary code.