CVE-2026-71506: Dolibarr < 24.0.0 Payments REST API Improper Authorization via Delete Endpoint

Published Aug 24, 2026
·
Updated

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that allows authenticated attackers with invoice-deletion rights to permanently delete any payment record by bypassing the intended payment-issuance rights check. Attackers can exploit this misconfigured permission check to zero paid amounts on invoices and remove entries from accounting exports, causing financial data integrity loss.

Affected Software

1 affected component
dolibarr Dolibarr<24.0.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Dolibarr to a version that resolves this vulnerability.

    Fixed in 24.0.0
  2. Compensating control

    Restrict access to the Dolibarr payments REST API delete endpoint to only users who are intended to have payment-deletion permissions (e.g., enforce least privilege at the application role level and/or at the network/ACL level).

Event History

Aug 24, 2026
CVE Published
via MITRE·07:01 PM
Data Sourced
via MITRE·07:01 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which users can exploit this issue?

An attacker must be authenticated and have invoice-deletion rights. They do not need the intended payment-issuance rights because the affected delete endpoint checks the wrong permission.

2

What records can be affected?

A qualifying user can permanently delete any payment record through the payments REST API delete endpoint. This can zero paid amounts on invoices and remove payment entries from accounting exports.

3

Which versions require remediation?

Dolibarr versions before 24.0.0 are affected. Upgrading to 24.0.0 or later addresses the vulnerable authorization check.

4

What can be done if an upgrade is not immediately possible?

Restrict invoice-deletion rights to only trusted users, since those rights enable exploitation of the affected endpoint. Review payment deletions and related invoice paid amounts and accounting exports for unexpected changes.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203