Feed/CVE-2026-10215
CVE-2026-10215MEDIUMCVSS 4.3

Dolibarr ERP CRM is vulnerable to Improper Authorization through its Leave Request REST API

Published Jun 1, 2026·Updated Jul 22, 2026

NVD Description

A security vulnerability has been detected in Dolibarr ERP CRM up to 23.0.1. Impacted is the function checkUserAccessToObject of the file htdocs/holiday/class/api_holidays.class.php of the component Leave Request REST API. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 23.0.2 is recommended to address this issue. The identifier of the patch is ee93b6f2f9dd0f6aeefe9d718ab3ab0a44326b73. Upgrading the affected component is advised.

Affected Packages (1)

dolibarr/dolibarrCOMPOSER
Fixed in = 15.0.3

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free