CVE-2026-71507: Dolibarr

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account write routes that allows authenticated attackers with third-party creation rights to create, replace, or delete bank account details of any company without requiring read access to that company. Attackers can inject attacker-controlled IBANs as creditor accounts, which are then written into regenerated SEPA credit-transfer files, redirecting outgoing payments to attacker-controlled accounts.

Affected products

  • Dolibarr Dolibarr: before 24.0.0 (fixed in 24.0.0)

Published 2026-08-24. Last modified 2026-09-08.