PT-2026-33504 · Dolibarr · Dolibarr

Lukasz-Rybak

·

Published

2026-04-17

·

Updated

2026-05-10

·

CVE-2026-23500

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Dolibarr versions prior to 23.0.0
Description Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. An authenticated administrator can achieve remote code execution as the web server user by injecting arbitrary OS commands into the MAIN ODT AS PDF configuration constant. This occurs during the ODT to PDF conversion process in 'odf.php', where the constant is concatenated directly into a shell command passed to the exec() function without proper sanitization. Approximately 56.8K services are estimated to be affected worldwide.
Recommendations Update to version 23.0.0. As a temporary workaround, restrict administrative access to the configuration settings for the MAIN ODT AS PDF constant to minimize the risk of exploitation.

Fix

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-23500
GHSA-W5J3-8FCR-H87W

Affected Products

Dolibarr