Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107706— Dolibarr before 24.0.2 Incorrect Authorization via updateextrafield.php

Quick assessment

Affected
Dolibarr dolibarr
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Dolibarr ERP/CRM 版本低于 24.0.2 在文件 中存在不正确的授权漏洞。该文件在写入额外字段(extrafield)值时,仅检查了读取权限。具有只读权限的已认证用户可通过 POST 方法提交 、 、 和 参数,持久化地修改可查看的第三方客户、产品、成员、项目或联系人记录的额外字段数据。

CVSS 4.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107706

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Dolibarr before 24.0.2 Incorrect Authorization via updateextrafield.php
Source: CVE Program / CVE List V5
Vulnerability Description
Dolibarr ERP CRM before 24.0.2 contains an incorrect authorization vulnerability in htdocs/core/ajax/updateextrafield.php that checks only read permission before writing extrafield values. Authenticated users with read-only access can POST objectType, objectId, field and value parameters to persistently modify extrafields on viewable third parties, products, members, projects or contacts.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Dolibarr dolibarr 0 ~ 24.0.2 -

II. Public POCs for CVE-2026-107706

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107706

请登录查看更多情报信息。

Other References for CVE-2026-107706 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-107706

No comments yet


Leave a comment