CVE-2026-71508
Received Received - Intake

Improper Authorization in Dolibarr User REST API Leading to Payroll Data Manipulation

Vulnerability report for CVE-2026-71508, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-24

Last updated on: 2026-08-24

Assigner: VulnCheck

Description

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update endpoint that allows attackers with user-write rights to modify payroll fields by exploiting an incomplete credential denylist that omits payroll columns. Attackers can rewrite salary, bonus, hourly rate, daily rate, and weekly hours for any user without holding payroll rights, with the modified values appearing in payroll export reports.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-24
Last Modified
2026-08-24
Generated
2026-08-24
AI Q&A
2026-08-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
dolibarr dolibarr to 24.0.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-71508 is an improper authorization vulnerability in Dolibarr before version 24.0.0. It allows attackers with basic user-write rights to modify payroll fields like salary, bonus, hourly rate, daily rate, and weekly hours for any user through the REST API update endpoint. The flaw exists because the API's deny-list omits payroll columns, enabling unauthorized changes that appear in payroll export reports.

Detection Guidance

To detect this vulnerability, check Dolibarr versions prior to 24.0.0. Review API logs for unauthorized modifications to user payroll fields like salary, bonus, hourly rate, daily rate, or weekly hours. Look for API calls to user update endpoints with suspicious payloads containing payroll-related parameters.

Impact Analysis

If exploited, this vulnerability could allow unauthorized users to alter payroll data, leading to incorrect salary payments, bonus adjustments, or hourly rate changes. These modifications may go unnoticed initially but will appear in payroll reports, potentially causing financial discrepancies, compliance violations, or disputes with employees.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR (data accuracy, integrity) and HIPAA (protected health information integrity) by allowing unauthorized modifications to sensitive payroll data. Incorrect payroll records may violate regulatory requirements for data accuracy and security.

Mitigation Strategies

Upgrade Dolibarr to version 24.0.0 or later to apply the patch. Review and restrict user permissions to ensure only authorized personnel can modify payroll fields. Monitor API access logs for unusual activity related to user updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71508. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart