Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that allows authenticated attackers with invoice-deletion rights to permanently delete any payment record by bypassing the intended payment-issuance rights check. Attackers can exploit this misconfigured permission check to zero paid amounts on invoices and remove entries from accounting exports, causing financial data integrity loss.
Metrics
Affected Vendors & Products
References
History
Fri, 28 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 24 Aug 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dolibarr
Dolibarr dolibarr |
|
| Vendors & Products |
Dolibarr
Dolibarr dolibarr |
Mon, 24 Aug 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that allows authenticated attackers with invoice-deletion rights to permanently delete any payment record by bypassing the intended payment-issuance rights check. Attackers can exploit this misconfigured permission check to zero paid amounts on invoices and remove entries from accounting exports, causing financial data integrity loss. | |
| Title | Dolibarr < 24.0.0 Payments REST API Improper Authorization via Delete Endpoint | |
| Weaknesses | CWE-863 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-08-24T19:01:47.408Z
Updated: 2026-08-29T11:47:37.389Z
Reserved: 2026-08-06T20:42:17.834Z
Link: CVE-2026-71506
Updated: 2026-08-26T15:46:19.265Z
Status : Deferred
Published: 2026-08-24T19:16:49.960
Modified: 2026-09-08T20:23:49.880
Link: CVE-2026-71506
No data.