Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-89012— Dolibarr 24.0.0 < 24.0.1 SQL Filter Denylist Bypass via sqlfilters Parameter

Quick assessment

Affected
Dolibarr Dolibarr
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Dolibarr 24.0.0(24.0.1 之前的版本)中存在一个针对 API 查询参数的大小写敏感拒绝列表绕过漏洞。该漏洞允许经过身份验证的攻击者通过提供受拒绝列表保护的字段的大写变体,来恢复受保护的数据库字段。攻击者可以利用数据库列解析的“大小写不敏感”特性,结合核心库中“大小写敏感”的拒绝列表检查,将前缀匹配谓词用作布尔预言机(Boolean Oracle),从而提取包括管理员账户在内的任意用户账户的完整密码哈希值。

CVSS 6.5 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-89012

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Dolibarr 24.0.0 < 24.0.1 SQL Filter Denylist Bypass via sqlfilters Parameter
Source: CVE Program / CVE List V5
Vulnerability Description
Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive denylist bypass vulnerability in the sqlfilters API query parameter that allows authenticated attackers to recover protected database fields by supplying uppercase variants of denylist-protected field names. Attackers can exploit the case-insensitive database column resolution against the case-sensitive denylist check in the core library to use prefix-matching predicates as a boolean oracle and extract full password hashes for any user account, including administrators.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
大小写敏感处理不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Dolibarr Dolibarr 24.0.0 ~ 24.0.1 -

II. Public POCs for CVE-2026-89012

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-89012

登录查看更多情报信息。

Patches & Fixes for CVE-2026-89012 (1)

Vendor Advisories for CVE-2026-89012 (1)

Vendor Pages for CVE-2026-89012 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-89012

No comments yet


Leave a comment