CVE-2026-71504
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers with only member-creation rights to reset the password of any user account, including the system administrator, without verifying password-change permissions. Attackers can supply an arbitrary user account identifier and new password in the request body to overwrite credentials and immediately lock out the legitimate account holder.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.26%
- CWE
- CWE-862, CWE-915
- Published
- 2026-08-24
- Last modified
- 2026-08-29
Affected products
- Dolibarr dolibarr
Weakness type
Related vulnerabilities
- CVE-2026-88915 — MISP Event Template Instantiation Bypasses Sharing Group and Tagging Authorization
- CVE-2026-88271 — GV-LPC2011/LPC2211 - SSVR Guest Configuration Overwrite and Administrative Credential Takeover
- CVE-2026-88270 — GV-LPC2011/LPC2211 - SSVR Guest Firmware-Mode Pre-Validation Service Teardown Denial of Service
- CVE-2026-88269 — GV-LPC2011/LPC2211 - SSVR Guest Configuration and Credential Disclosure
- CVE-2026-14873 — Bulk Password Reset <= 1.3.3 - Authenticated (Subscriber+) Arbitrary Password Reset
- CVE-2026-18594 — Advanced Contact form 7 DB <= 2.1.3 - Missing Authorization to Authenticated (Custom+) Unauthorized Data Import via 'import_cf7_id'
- CVE-2026-15823 — Builderall for WordPress <= 3.0.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Modification via 'ba_cheetah_data[post_id]' Parameter
- CVE-2026-87997 — Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions