CVE-2026-78160: Dolibarr ERP User Notes note.php authorization
A vulnerability has been found in Dolibarr ERP up to 18.0.10/22.0.5/23.0.3. This issue affects some unknown processing of the file /user/note.php of the component User Notes Handler. The manipulation of the argument ID leads to authorization bypass. The attack can be initiated remotely. Upgrading to version 23.0.4 and 24.0.0 is capable of addressing this issue. The identifier of the patch is 9b5229ef3a9b58d00252d327936b022fb739f149. Upgrading the affected component is advised.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dolibarr ERPto a version that resolves this vulnerability.Fixed in 23.0.4Patch 9b5229ef3a9b58d00252d327936b022fb739f149 - Upgrade
Upgrade
Dolibarr ERPto a version that resolves this vulnerability.Fixed in 24.0.0Patch 9b5229ef3a9b58d00252d327936b022fb739f149
Event History
Frequently Asked Questions
Which installations are affected?
Dolibarr ERP versions up to 18.0.10, 22.0.5, and 23.0.3 are affected. Versions 23.0.4 and 24.0.0 address the issue.
What does an attacker need to exploit this issue?
The attack can be initiated remotely and requires low privileges. Exploitation involves manipulating the ID argument handled by /user/note.php.
What is the impact of successful exploitation?
The vulnerability allows an authorization bypass in the User Notes Handler. The supplied severity vector indicates potential low-impact compromise of confidentiality, integrity, and availability.
What should teams do if they are running an affected release?
Upgrade Dolibarr ERP to version 23.0.4 or 24.0.0. The referenced patch identifier is 9b5229ef3a9b58d00252d327936b022fb739f149.