CVE-2026-71504 is a critical improper authorization vulnerability in Dolibarr versions before 24.0.0 affecting the Members REST API. Attackers who possess only member-creation rights can exploit this flaw to reset the password of any user account, including the system administrator, without needing password-change permissions. The attack is performed by supplying an arbitrary user account identifier and a new password in the request body, effectively overwriting credentials. This allows an attacker to immediately lock out the legitimate account holder and gain unauthorized access. The vulnerability is classified as a mass assignment issue. A fix has been released in Dolibarr version 24.0.0. Multiple sources, including NVD, VulnCheck, and CodeAnt AI, have documented this vulnerability. Organizations using Dolibarr should upgrade immediately to version 24.0.0 or later.