PT-2026-36693 · Unknown · Dolibarr Erp/Crm

Yan1451

·

Published

2026-05-03

·

Updated

2026-05-03

·

CVE-2026-7689

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Dolibarr ERP CRM versions prior to 23.0.3
Description A flaw in the Online Signature Module allows for improper verification of cryptographic signatures. This issue occurs within the dol verifyHash() function located in the htdocs/core/lib/security.lib.php library. A remote attacker can exploit this weakness, although the attack is considered highly complex and difficult to execute.
Recommendations Update to a version later than 23.0.2. As a temporary workaround, restrict access to the dol verifyHash() function in the htdocs/core/lib/security.lib.php library to minimize the risk of exploitation.

Exploit

Fix

Insufficient Verification of Data Authenticity

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7689
GHSA-JGGH-5RMH-R6H5

Affected Products

Dolibarr Erp/Crm