← Back to overview

Dolibarr versions before 24.0.0 contain an improper authorization vulnerability in the payments REST API delete endpoint. Authenticated attackers with invoice-deletion rights can permanently delete any payment record by bypassing the intended payment-issuance rights check. This misconfigured permission check allows attackers to zero out paid amounts on invoices and remove entries from accounting exports. The vulnerability results in financial data integrity loss, making it particularly dangerous for organizations relying on Dolibarr for accounting and financial management. The issue has been addressed in Dolibarr version 24.0.0, with a corresponding commit available on GitHub.

Affected products

  • Dolibarr before 24.0.0

Related CVE's

  • CVE-2026-71506

Categories

  • Enterprise Applications
  • Identity & Access
  • Web Technologies