Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 11 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dolibarr 23.0.4 before 24.0.1 ontains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files through the document storage endpoints by supplying a crafted hashp parameter value. Attackers can send a request with hashp=shared to skip token validation while satisfying the authorization condition in htdocs/document.php and htdocs/viewimage.php, gaining access to application logs, uploaded business documents, database backups containing password hashes, and files belonging to other multicompany entities. | |
| Title | Dolibarr 23.0.4 < 24.0.1 Authorization Bypass via hashp Parameter in document.php | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-11T18:06:39.464Z
Reserved: 2026-09-10T16:23:54.471Z
Link: CVE-2026-89013
No data.
Status : Received
Published: 2026-09-11T16:17:48.853
Modified: 2026-09-11T16:17:48.853
Link: CVE-2026-89013
No data.
OpenCVE Enrichment
No data.