HIGH
Dolibarr has an Authenticated Remote Code Execution via eval() injection in user extrafields
Published May 8, 2026
8.6
HIGHCVSS 4.0
EPSS 0.88%
Description
Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Versions 22.0.2 and earlier contains an authenticated remote code execution vulnerability in the user extrafields functionality. User-controlled input from the "computed value" field is passed to PHP's `eval()` function without adequate sanitization, allowing authenticated administrators to execute arbitrary PHP code on the server. As of time of publication, no patched versions are available.
Affected products
-
- Version <= 22.0.2StatusaffectedConstraints-
- Version
- ≤ 22.0.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-209752 Advisory
- https://github.com/Dolibarr/dolibarr/blob/22.0.2/htdocs/core/lib/functions.lib.php x_refsource_MISCPatch
- https://medium.com/@abduxalilovjavohir/dolibarr-erp-authenticated-remote-code-execution-via-eval-injection-in-user-extrafields-dfc305d0118e exploitx_refsource_CONFIRMThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-209752 | Advisory | |
| https://github.com/Dolibarr/dolibarr/blob/22.0.2/htdocs/core/lib/functions.lib.php | x_refsource_MISCPatch | |
| https://medium.com/@abduxalilovjavohir/dolibarr-erp-authenticated-remote-code-execution-via-eval-injection-in-user-extrafields-dfc305d0118e | exploitx_refsource_CONFIRMThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 8, 2026
Updated May 8, 2026
Reserved Dec 8, 2025
Link CVE-2025-67486
CISA Vulnrichment
Updated May 8, 2026
ENISA EUVD
EUVD-2025-209752 Assigner GitHub_M
Published May 8, 2026
Updated May 8, 2026
Exploited since n/a
Link EUVD-2025-209752