Medium severity4.3NVD Advisory· Published Oct 8, 2026· Updated Oct 8, 2026
CVE-2026-107706
CVE-2026-107706
Description
Dolibarr ERP CRM before 24.0.2 contains an incorrect authorization vulnerability in htdocs/core/ajax/updateextrafield.php that checks only read permission before writing extrafield values. Authenticated users with read-only access can POST objectType, objectId, field and value parameters to persistently modify extrafields on viewable third parties, products, members, projects or contacts.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.