Home

Description

A security vulnerability has been detected in Dolibarr ERP CRM up to 23.0.1. Impacted is the function checkUserAccessToObject of the file htdocs/holiday/class/api_holidays.class.php of the component Leave Request REST API. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 23.0.2 is recommended to address this issue. The identifier of the patch is ee93b6f2f9dd0f6aeefe9d718ab3ab0a44326b73. Upgrading the affected component is advised.

PUBLISHED Reserved 2026-05-31 | Published 2026-06-01 | Updated 2026-06-01 | Assigner VulDB




MEDIUM: 5.3CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
MEDIUM: 4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C
MEDIUM: 4.3CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C
4.0AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:OF/RC:C

Problem types

Improper Authorization

Incorrect Privilege Assignment

Product status

23.0.0
affected

23.0.1
affected

23.0.2
unaffected

Timeline

2026-05-31:Advisory disclosed
2026-05-31:VulDB entry created
2026-05-31:VulDB entry last update

Credits

Mitch311 (VulDB User) reporter

References

vuldb.com/vuln/367494 (VDB-367494 | Dolibarr ERP CRM Leave Request REST API api_holidays.class.php checkUserAccessToObject improper authorization) vdb-entry technical-description

vuldb.com/vuln/367494/cti (VDB-367494 | CTI Indicators (IOB, IOC, TTP, IOA)) signature permissions-required

vuldb.com/cve/CVE-2026-10215 (CVE-2026-10215 | CVE Analysis and Report) third-party-advisory

vuldb.com/submit/821930 (Submit #821930 | Dolibarr Dolibarr ERP/CRM <=23.0.1 Incorrect Authorization) third-party-advisory

github.com/Dolibarr/dolibarr/issues/37752 issue-tracking

github.com/Dolibarr/dolibarr/issues/37752 issue-tracking

github.com/...equest_API_Horizontal_Unauthorized_Read_en.pdf exploit

github.com/...ommit/ee93b6f2f9dd0f6aeefe9d718ab3ab0a44326b73 patch

github.com/Dolibarr/dolibarr/releases/tag/23.0.2 patch

cve.org (CVE-2026-10215)

nvd.nist.gov (CVE-2026-10215)

Download JSON