CVE-2026-107706
Deferred Deferred - Pending Action

Incorrect Authorization in Dolibarr ERP CRM Allows Extrafield Modification

Vulnerability report for CVE-2026-107706, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

Dolibarr ERP CRM before 24.0.2 contains an incorrect authorization vulnerability in htdocs/core/ajax/updateextrafield.php that checks only read permission before writing extrafield values. Authenticated users with read-only access can POST objectType, objectId, field and value parameters to persistently modify extrafields on viewable third parties, products, members, projects or contacts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Dolibarr dolibarr 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Dolibarr ERP CRM before version 24.0.2 has an incorrect authorization vulnerability in the file updateextrafield.php. The system only checks read permissions before allowing write operations, enabling authenticated users with read-only access to modify extrafields on third parties, products, members, projects, or contacts by sending POST requests with parameters objectType, objectId, field, and value.

Detection Guidance

To detect this vulnerability, inspect Dolibarr's updateextrafield.php file for improper permission checks. Check if the script validates only read permissions before allowing write operations. Review POST requests to this endpoint for parameters objectType, objectId, field, and value from users with read-only access.

Impact Analysis

An attacker with read-only access could exploit this to persistently modify critical data like customer details, project information, or member records. This could lead to data corruption, unauthorized changes in business records, or misinformation affecting operations and decision-making.

Compliance Impact

This vulnerability could lead to unauthorized data modifications, violating integrity requirements in GDPR and HIPAA. Persistent changes to personal or sensitive data without proper authorization may result in non-compliance, potential fines, and loss of trust in data handling practices.

Mitigation Strategies

Upgrade Dolibarr to version 24.0.2 or later to apply the security patch. Ensure the restrictedArea() function enforces write permission checks in AJAX components. Review and restrict user permissions to prevent unauthorized modifications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107706. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart