CVE-2026-71508

Dolibarr < 24.0.0 REST API Improper Authorization via User Update Endpoint

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update endpoint that allows attackers with user-write rights to modify payroll fields by exploiting an incomplete credential denylist that omits payroll columns. Attackers can rewrite salary, bonus, hourly rate, daily rate, and weekly hours for any user without holding payroll rights, with the modified values appearing in payroll export reports.


We have discovered 379 live websites that are affected by CVE-2026-71508.

Run a Free Instant Scan




Affected Software

Product  Dolibarr
Category Customer Relationship Management
Vulnerable Domains379 live websites (100% of Dolibarr install base)
Vulnerable Versions
  • from 0 through 24
Vulnerable Versions Count54 versions ( 98% of all versions)



Details

  • Published - Aug 24, 2026
  • Updated - Aug 24, 2026

Credits

  • CodeAnt AI Security Research (finder)
  • VulnCheck (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-71508
United States31 websites



France234 websites
Germany28 websites
Spain15 websites
Italy13 websites
Switzerland7 websites
GB7 websites
Brazil4 websites
Mexico4 websites
Netherlands4 websites

Website Distribution by TLD

Number of websites using CVE-2026-71508
.fr119 websites
.com101 websites
.net21 websites
.org15 websites
.de15 websites
.it13 websites
.es9 websites
.eu7 websites
.ch4 websites
.be3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-71508

Top websites that are affected by CVE-2026-71508. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com France***,***
**********.org France*,***,***
***************.net United States*,***,***
************.com Germany*,***,***
*****************.de Germany*,***,***
********.com France*,***,***
*****.**********.fr France*,***,***
*******.**************.fr France*,***,***
***.**********.de Germany*,***,***
***.**********.fr France*,***,***
See full domain list

FAQ

A total of 379 websites have been identified as vulnerable to CVE-2026-71508, based on global website indexing conducted by WebTechSurvey.
The Dolibarr is affected by the CVE-2026-71508 vulnerability.
Dolibarr versions up to 24 are vulnerable to CVE-2026-71508.
CVE-2026-71508 is resolved in version 24 of Dolibarr.