Skip to main content
QUIETLYTIC
Vulnerability

Dolibarr ERP/CRM Vulnerability (CVE-2026-89013)

CVE-2026-89013 is a CVSS 7.5 unauthenticated authorization bypass in Dolibarr document endpoints, per VulnCheck alone.

CVE-2026-89013
Threat Level
HIGH
CVSS
7.5
Status
Active Exploitation
Confidence
Medium
Affected Products
Dolibarr ERP/CRM (23.0.4 before 24.0.1)

CVE-2026-89013 carries a CVSS 3.1 base score of 7.5 against Dolibarr, an open-source ERP/CRM platform. NVD classifies it as CWE-863 (Incorrect Authorization) and states the flaw affects version 23.0.4 up to (but not including) 24.0.1. VulnCheck’s KEV feed reports the CVE as exploited, dated September 17, 2026.

That exploitation report is single-sourced. CISA has not added CVE-2026-89013 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.

What the flaw is

NVD’s description states Dolibarr’s document-retrieval and image-viewing endpoints (document.php and viewimage.php) contain a token-validation gap tied to a specific request parameter: a particular parameter value causes the endpoints’ authorization check to be satisfied without the normal access token actually being validated. NVD states this lets an unauthenticated attacker read arbitrary files served through those endpoints, including application logs, uploaded business documents, database backups containing password hashes, and files belonging to other tenant entities in multi-company Dolibarr deployments.

We are deliberately not reproducing the specific parameter value NVD’s description identifies as triggering the bypass, since doing so would function as a directly usable exploitation instruction rather than vulnerability reporting; readers needing that detail for authorized testing or patch verification should consult the linked vendor fix commit.

Evidence and confidence

  • Medium confidence — the CVSS 7.5 score, the vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), the CWE-863 classification, the affected version range, and the described mechanism all trace to NVD alone in our current ingestion, corroborated by Dolibarr’s own linked fix commit and release. The exploitation report traces to VulnCheck KEV alone.

Our source data does not carry an EPSS score or percentile for this CVE. No field is in conflict between our two sources.

Why this matters

This flaw’s impact list is unusually broad for a single vulnerability: application logs, uploaded business documents, database backups containing password hashes, and cross-tenant data in multi-company installations are all named by NVD as reachable through the same unauthenticated bypass. ERP/CRM platforms like Dolibarr centralize exactly the kind of sensitive business and customer data this flaw exposes, and the multi-company angle means a single vulnerable instance can expose data belonging to multiple otherwise-isolated organizational tenants. Any organization running a pre-24.0.1 Dolibarr deployment with these endpoints internet-facing should treat this as an active, unauthenticated data-exposure risk.

Frequently Asked Questions

What is CVE-2026-89013? A CVSS 7.5 incorrect authorization vulnerability (CWE-863) in Dolibarr ERP/CRM versions 23.0.4 up to 24.0.1, allowing unauthenticated attackers to bypass token validation on document-retrieval endpoints and read arbitrary files, including credential and business data.

Is CVE-2026-89013 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 17, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.

Do I need an account to exploit this? No. NVD’s description and the CVSS vector both confirm this is exploitable without authentication.

What kind of data is exposed? Per NVD: application logs, uploaded business documents, database backups containing password hashes, and — in multi-company Dolibarr deployments — files belonging to other tenant entities.

Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.

Which version fixes this? Version 24.0.1, per NVD and Dolibarr’s own release notes.


Severity, vector, weakness classification, affected versions, and impact sourced from the National Vulnerability Database record for CVE-2026-89013, corroborated by Dolibarr’s own fix commit. Exploitation status and the September 17, 2026 catalog date reported by VulnCheck’s own advisory. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools