CVE-2026-71505

Dolibarr < 24.0.0 REST API Broken Object-Level Authorization via Third-Party Write Route

Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site account write routes that allows authenticated attackers with third-party creation rights to overwrite the WebPortal password of any company by bypassing per-object access checks that are only enforced on read routes. Attackers can replace the victim company's WebPortal password through the write endpoint, authenticate as that company to access its invoice data, and also obtain the victim's previous password verifier from the API response.


We have discovered 379 live websites that are affected by CVE-2026-71505.

Run a Free Instant Scan




Affected Software

Product  Dolibarr
Category Customer Relationship Management
Vulnerable Domains379 live websites (100% of Dolibarr install base)
Vulnerable Versions
  • from 0 through 24
Vulnerable Versions Count54 versions ( 98% of all versions)



Details

  • Published - Aug 24, 2026
  • Updated - Aug 24, 2026

Credits

  • CodeAnt AI Security Research (finder)
  • VulnCheck (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-71505
United States31 websites



France234 websites
Germany28 websites
Spain15 websites
Italy13 websites
Switzerland7 websites
GB7 websites
Brazil4 websites
Mexico4 websites
Netherlands4 websites

Website Distribution by TLD

Number of websites using CVE-2026-71505
.fr119 websites
.com101 websites
.net21 websites
.org15 websites
.de15 websites
.it13 websites
.es9 websites
.eu7 websites
.ch4 websites
.be3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-71505

Top websites that are affected by CVE-2026-71505. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com France***,***
**********.org France*,***,***
***************.net United States*,***,***
************.com Germany*,***,***
*****************.de Germany*,***,***
********.com France*,***,***
*****.**********.fr France*,***,***
*******.**************.fr France*,***,***
***.**********.de Germany*,***,***
***.**********.fr France*,***,***
See full domain list

FAQ

A total of 379 websites have been identified as vulnerable to CVE-2026-71505, based on global website indexing conducted by WebTechSurvey.
The Dolibarr is affected by the CVE-2026-71505 vulnerability.
Dolibarr versions up to 24 are vulnerable to CVE-2026-71505.
CVE-2026-71505 is resolved in version 24 of Dolibarr.