HIGH
Dolibarr 23.0.4 < 24.0.1 Authorization Bypass via hashp Parameter in document.php
Published Sep 11, 2026
8.7
HIGHCVSS 4.0
EPSS 1.56%
Description
Dolibarr 23.0.4 before 24.0.1 contains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files through the document storage endpoints by supplying a crafted hashp parameter value. Attackers can send a request with hashp=shared to skip token validation while satisfying the authorization condition in htdocs/document.php and htdocs/viewimage.php, gaining access to application logs, uploaded business documents, database backups containing password hashes, and files belonging to other multicompany entities.
Affected products
-
- Version 23.0.4StatusaffectedConstraints<24.0.1
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-76144 Advisory
- https://github.com/Dolibarr/dolibarr/commit/cd05688dbed8a4af6eef32faf4fc1e823a37bce9 patch
- https://github.com/Dolibarr/dolibarr/releases/tag/24.0.1 release-notes
- https://www.vulncheck.com/advisories/dolibarr-authorization-bypass-via-hashp-parameter-in-document-php third-party-advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Sep 11, 2026
Updated Oct 1, 2026
Reserved Sep 10, 2026
Link CVE-2026-89013
CISA Vulnrichment
Updated Sep 11, 2026
ENISA EUVD
EUVD-2026-76144 Assigner VulnCheck
Published Sep 11, 2026
Updated Oct 1, 2026
Exploited since n/a
Link EUVD-2026-76144