CVE-2026-71510: Dolibarr < 24.0.0 Users REST API SQL Injection via filter parameter

Published Aug 24, 2026
·
Updated

Dolibarr before 24.0.0 contains a SQL injection vulnerability in the users REST API that allows authenticated attackers with user-read rights to extract sensitive data by splicing unsanitized filter parameters into SQL WHERE clauses without column restrictions. Attackers can perform binary search on numeric fields and LIKE prefix iteration on string fields to recover salary figures and password verifiers omitted from normal API responses, while raw database error messages in the same endpoint enable column name enumeration.

Affected Software

1 affected component
dolibarr Dolibarr<24.0.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Dolibarr Users REST API to a version that resolves this vulnerability.

    Fixed in 24.0.0
  2. Compensating control

    Restrict access to the Dolibarr users REST API endpoint (with the vulnerable filter parameter) to the minimum set of authenticated users with user-read rights, to limit who can exploit the SQL injection.

Event History

Aug 24, 2026
CVE Published
via MITRE·07:05 PM
Data Sourced
via MITRE·07:05 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this vulnerability?

An attacker must be authenticated and have user-read rights in Dolibarr. The vulnerable REST API is network-accessible, and no user interaction is required.

2

What information could be exposed?

An attacker can extract sensitive database data, including salary figures and password verifiers that are omitted from normal API responses. Error messages from the endpoint can also be used to enumerate database column names.

3

Which versions are affected and what is the fix?

Dolibarr versions before 24.0.0 are affected. Upgrade to version 24.0.0 or later.

4

What can be done if an upgrade is not immediately possible?

Restrict access to the users REST API and remove user-read rights from accounts that do not require them. Limiting authenticated access reduces the set of users able to send malicious filter parameters.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203