High severity8.1NVD Advisory· Published Aug 24, 2026· Updated Sep 8, 2026
CVE-2026-71506
CVE-2026-71506
Description
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that allows authenticated attackers with invoice-deletion rights to permanently delete any payment record by bypassing the intended payment-issuance rights check. Attackers can exploit this misconfigured permission check to zero paid amounts on invoices and remove entries from accounting exports, causing financial data integrity loss.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
4- codeant.ai/security-research/cve-2026-71506-dolibarr-payment-deletion-via-incorrect-authorizationnvd
- github.com/Dolibarr/dolibarr/commit/e01a12ffea4675f5bcc1c886f06ec6a29d5e4801nvd
- github.com/Dolibarr/dolibarr/releases/tag/24.0.0nvd
- www.vulncheck.com/advisories/dolibarr-payments-rest-api-improper-authorization-via-delete-endpointnvd
News mentions
0No linked articles in our index yet.