High severity8.1NVD Advisory· Published Aug 24, 2026
CVE-2026-71504
CVE-2026-71504
Description
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers with only member-creation rights to reset the password of any user account, including the system administrator, without verifying password-change permissions. Attackers can supply an arbitrary user account identifier and new password in the request body to overwrite credentials and immediately lock out the legitimate account holder.
Affected products
1Patches
Vulnerability mechanics
References
4- codeant.ai/security-research/cve-2026-71504-mass-assignment-in-members-api-via-passnvd
- github.com/Dolibarr/dolibarr/commit/fbf476cc5d9a21b16bfa04ab17d4e84eda38d7cenvd
- github.com/Dolibarr/dolibarr/releases/tag/24.0.0nvd
- www.vulncheck.com/advisories/dolibarr-members-rest-api-improper-authorization-via-password-resetnvd
News mentions
0No linked articles in our index yet.