PT-2026-45140 · Unknown · Dolibarr Erp/Crm

·

CVE-2026-10154

·

Published

2026-05-30

·

Updated

2026-05-31

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X
Name of the Vulnerable Software and Affected Versions Dolibarr ERP CRM versions 23.0.0 through 23.0.2
Description An issue exists in an unknown function within the file 'htdocs/user/messaging.php' that allows for remote authorization bypass. This occurs through the manipulation of the ID argument.
Recommendations Upgrade to version 23.0.3.

Exploit

Fix

IDOR

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10154

Affected Products

Dolibarr Erp/Crm