Unknown · Dolibarr Erp/Crm · CVE-2026-10154
**Name of the Vulnerable Software and Affected Versions**
Dolibarr ERP CRM versions 23.0.0 through 23.0.2
**Description**
An issue exists in an unknown function within the file 'htdocs/user/messaging.php' that allows for remote authorization bypass. This occurs through the manipulation of the `ID` argument.
**Recommendations**
Upgrade to version 23.0.3.