Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. dolibarr/dolibarr
  4. ›
  5. CVE-2026-10215

CVE-2026-10215: Dolibarr ERP CRM is vulnerable to Improper Authorization through its Leave Request REST API

June 1, 2026 (updated July 7, 2026)

A security vulnerability has been detected in Dolibarr ERP CRM up to 23.0.1. Impacted is the function checkUserAccessToObject of the file htdocs/holiday/class/api_holidays.class.php of the component Leave Request REST API. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 23.0.2 is recommended to address this issue. The identifier of the patch is ee93b6f2f9dd0f6aeefe9d718ab3ab0a44326b73. Upgrading the affected component is advised.

References

  • github.com/Dolibarr/dolibarr/commit/ee93b6f2f9dd0f6aeefe9d718ab3ab0a44326b73
  • github.com/Dolibarr/dolibarr/issues/37752
  • github.com/Dolibarr/dolibarr/issues/37752
  • github.com/Dolibarr/dolibarr/releases/tag/23.0.2
  • github.com/advisories/GHSA-7fg5-vc77-69fp
  • github.com/user-attachments/files/26487388/2_Dolibarr_Leave_Request_API_Horizontal_Unauthorized_Read_en.pdf
  • nvd.nist.gov/vuln/detail/CVE-2026-10215
  • vuldb.com/cve/CVE-2026-10215
  • vuldb.com/submit/821930
  • vuldb.com/vuln/367494
  • vuldb.com/vuln/367494/cti

Code Behaviors & Features

Detect and mitigate CVE-2026-10215 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 15.0.3

Solution

Unfortunately, there is no solution available yet.

Impact 4.3 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-266: Incorrect Privilege Assignment

Source file

packagist/dolibarr/dolibarr/CVE-2026-10215.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Mon, 13 Jul 2026 12:19:45 +0000.