CVE-2026-23500: Dolibarr Erp/crm

Critical severity, CVSS 9.1. EPSS: 0.9% chance of exploitation in the next 30 days.

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions prior to 23.0.0 , the ODT to PDF conversion process in odf.php concatenates the MAIN_ODT_AS_PDF configuration constant directly into a shell command passed to exec() without sanitization. An authenticated administrator can inject arbitrary OS commands via this constant using command separators, achieving remote code execution as the web server user when any ODT template is generated. This issue has been fixed in version 23.0.0.

Affected products

  • Dolibarr Dolibarr Erp/crm: before 23.0.0 (fixed in 23.0.0)

Published 2026-04-17. Last modified 2026-06-17.