https://reddit.com/r/netsec/comments/1skazzv/cve202622666_dolibarr_2300_dol_eval_whitelist/: CVE-2026-22666: Dolibarr 23.0.0 dol_eval() whitelist bypass -> RCE (full write-up + PoC)
Published Apr 13, 2026
·Updated
Affected Software
1 affected component
dolibarr Dolibarr=23.0.0
Frequently Asked Questions
1
What is the severity of CVE-2026-22666?
CVE-2026-22666 has a critical severity level due to its potential for remote code execution.
2
How do I fix CVE-2026-22666?
To fix CVE-2026-22666, upgrade to Dolibarr version 23.0.1 or later where the vulnerability is patched.
3
What software is affected by CVE-2026-22666?
CVE-2026-22666 affects Dolibarr versions prior to 23.0.1.
4
What are the potential impacts of CVE-2026-22666?
The potential impacts of CVE-2026-22666 include unauthorized remote code execution on affected systems.
5
How can CVE-2026-22666 be exploited?
CVE-2026-22666 can be exploited through the misuse of the dol_eval() function due to the ineffective whitelist enforcement.