CVE-2026-58376: Dolibarr - SQL Injection via sqlfilters Parameter in Multiple REST API List Endpoints

Published Jun 30, 2026
·
Updated

Dolibarr through 23.0.3, fixed in commit 14db36e, contains a sql injection vulnerability that allows authenticated API users to exfiltrate arbitrary database contents by supplying malicious values to the sqlfilters query parameter in the setup dictionary and multicurrencies REST API endpoints. The affected endpoints in apisetup.class.php and apimulticurrencies.class.php validate sqlfilters only for balanced parentheses and rewrite matched triplets, allowing text placed outside the expected shape such as an appended UNION SELECT to be concatenated into the SQL WHERE clause unmodified, enabling retrieval of sensitive data including password hashes and API keys.

Affected Software

1 affected component
dolibarr Dolibarr<=23.0.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Dolibarr to a version that resolves this vulnerability.

    Fixed in 23.0.3Patch 14db36e
  2. Compensating control

    Restrict access to the affected Dolibarr REST API endpoints (api_setup.class.php and api_multicurrencies.class.php) so that only trusted, authenticated users can call them, reducing the risk of SQL injection data exfiltration via the sqlfilters query parameter.

Event History

Jun 30, 2026
CVE Published
via MITRE·03:59 PM
Data Sourced
via MITRE·03:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-58376?

CVE-2026-58376 has a high severity rating of 7.6.

2

How do I fix CVE-2026-58376?

CVE-2026-58376 can be fixed by upgrading to Dolibarr version 23.0.4 or later, which addresses the SQL injection vulnerability.

3

What type of vulnerability is CVE-2026-58376?

CVE-2026-58376 is an SQL injection vulnerability found in Dolibarr.

4

Who is affected by CVE-2026-58376?

Authenticated API users utilizing the affected REST API endpoints in Dolibarr versions prior to 23.0.4 are at risk from CVE-2026-58376.

5

What can attackers do with CVE-2026-58376?

Attackers exploiting CVE-2026-58376 can exfiltrate arbitrary database contents by supplying malicious values to the sqlfilters parameter.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203