CVE-2026-77686 PUBLISHED

Dolibarr Account card.php improper authorization

Assigner: VulDB
Reserved: 21.08.2026 Published: 21.08.2026 Updated: 21.08.2026

A weakness has been identified in Dolibarr up to 23.0.4. This affects an unknown part of the file htdocs/user/card.php of the component Account Handler. This manipulation of the argument ID causes improper authorization. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 24.0.0 is able to mitigate this issue. Patch name: b2a2c995537cb6282383b5e903cb5ffa29b823e6. The affected component should be upgraded.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 5.3

Product Status

Vendor n/a
Product Dolibarr
Versions
  • Version 23.0.0 is affected
  • Version 23.0.1 is affected
  • Version 23.0.2 is affected
  • Version 23.0.3 is affected
  • Version 23.0.4 is affected
  • Version 24.0.0 is unaffected

Credits

  • Abderrahmane Aksoum (VulDB User) reporter

References

Problem Types

  • Improper Authorization CWE
  • Incorrect Privilege Assignment CWE