CVE-2026-71504

Dolibarr < 24.0.0 Members REST API Improper Authorization via Password Reset

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers with only member-creation rights to reset the password of any user account, including the system administrator, without verifying password-change permissions. Attackers can supply an arbitrary user account identifier and new password in the request body to overwrite credentials and immediately lock out the legitimate account holder.


We have discovered 379 live websites that are affected by CVE-2026-71504.

Run a Free Instant Scan




Affected Software

Product  Dolibarr
Category Customer Relationship Management
Vulnerable Domains379 live websites (100% of Dolibarr install base)
Vulnerable Versions
  • from 0 through 24
Vulnerable Versions Count54 versions ( 98% of all versions)



Details

  • Published - Aug 24, 2026
  • Updated - Aug 27, 2026

Credits

  • CodeAnt AI Security Research (finder)
  • VulnCheck (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-71504
United States31 websites



France234 websites
Germany28 websites
Spain15 websites
Italy13 websites
Switzerland7 websites
GB7 websites
Brazil4 websites
Mexico4 websites
Netherlands4 websites

Website Distribution by TLD

Number of websites using CVE-2026-71504
.fr119 websites
.com101 websites
.net21 websites
.org15 websites
.de15 websites
.it13 websites
.es9 websites
.eu7 websites
.ch4 websites
.be3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-71504

Top websites that are affected by CVE-2026-71504. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com France***,***
**********.org France*,***,***
***************.net United States*,***,***
************.com Germany*,***,***
*****************.de Germany*,***,***
********.com France*,***,***
*****.**********.fr France*,***,***
*******.**************.fr France*,***,***
***.**********.de Germany*,***,***
***.**********.fr France*,***,***
See full domain list

FAQ

A total of 379 websites have been identified as vulnerable to CVE-2026-71504, based on global website indexing conducted by WebTechSurvey.
The Dolibarr is affected by the CVE-2026-71504 vulnerability.
Dolibarr versions up to 24 are vulnerable to CVE-2026-71504.
CVE-2026-71504 is resolved in version 24 of Dolibarr.