CVE-2026-107706: Dolibarr

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Dolibarr ERP CRM before 24.0.2 contains an incorrect authorization vulnerability in htdocs/core/ajax/updateextrafield.php that checks only read permission before writing extrafield values. Authenticated users with read-only access can POST objectType, objectId, field and value parameters to persistently modify extrafields on viewable third parties, products, members, projects or contacts.

Affected products

  • Dolibarr Dolibarr: before 24.0.2 (fixed in 24.0.2)

Published 2026-10-08. Last modified 2026-10-08.