PT-2026-33504 · Dolibarr · Dolibarr
Lukasz-Rybak
·
Published
2026-04-17
·
Updated
2026-05-10
·
CVE-2026-23500
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Dolibarr versions prior to 23.0.0
Description
Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. An authenticated administrator can achieve remote code execution as the web server user by injecting arbitrary OS commands into the
MAIN ODT AS PDF configuration constant. This occurs during the ODT to PDF conversion process in 'odf.php', where the constant is concatenated directly into a shell command passed to the exec() function without proper sanitization. Approximately 56.8K services are estimated to be affected worldwide.Recommendations
Update to version 23.0.0.
As a temporary workaround, restrict administrative access to the configuration settings for the
MAIN ODT AS PDF constant to minimize the risk of exploitation.Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dolibarr