Back

HIGH

Dolibarr has an Authenticated Remote Code Execution via eval() injection in user extrafields

Published May 8, 2026

Description

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Versions 22.0.2 and earlier contains an authenticated remote code execution vulnerability in the user extrafields functionality. User-controlled input from the "computed value" field is passed to PHP's `eval()` function without adequate sanitization, allowing authenticated administrators to execute arbitrary PHP code on the server. As of time of publication, no patched versions are available.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 8, 2026
Updated May 8, 2026
Reserved Dec 8, 2025
CISA Vulnrichment
Updated May 8, 2026
NVD
Status Analyzed
Modified Oct 5, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published May 8, 2026
Updated May 8, 2026
Exploited since n/a
EUVD-2025-209752