{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/dolibarr-23.0.4---24.0.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:dolibarr:dolibarr:23.0.4:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-89013"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=BAAF8349-AB02-5C71-B94E-0F3276B4A5E9\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["Dolibarr (23.0.4 - 24.0.0)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","authorization-bypass"],"_cs_type":"advisory","_cs_vendors":["Dolibarr"],"content_html":"\u003cp\u003eDolibarr versions 23.0.4 through 24.0.0 contain an authorization bypass vulnerability (CVE-2026-89013) that enables unauthenticated remote attackers to retrieve arbitrary files from the application server. The vulnerability exists within the document storage handling logic found in htdocs/document.php and htdocs/viewimage.php. By supplying a crafted 'hashp=shared' parameter in an HTTP request, an attacker can trick the application into skipping necessary token validation checks. This allows the attacker to bypass access controls and satisfy the authorization conditions required to read sensitive data. Impacted files include application logs, confidential business documents, database backups containing password hashes, and files stored across different multicompany entities. This vulnerability is critical due to the potential for full database compromise and unauthorized exposure of business-critical information.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify the target Dolibarr instance.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP GET or POST request targeting htdocs/document.php or htdocs/viewimage.php.\u003c/li\u003e\n\u003cli\u003eAttacker appends the 'hashp=shared' parameter to the URI query string to invoke the vulnerable code path.\u003c/li\u003e\n\u003cli\u003eThe application processes the request, incorrectly bypassing the authentication token verification logic.\u003c/li\u003e\n\u003cli\u003eThe application returns the requested file contents directly in the HTTP response body.\u003c/li\u003e\n\u003cli\u003eAttacker exfiltrates sensitive files, such as database backups or internal configuration logs.\u003c/li\u003e\n\u003cli\u003eAttacker uses credentials or metadata found in the exfiltrated files to escalate privileges or move laterally.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to unauthorized disclosure of sensitive business information. Potential impacts include access to database backups containing password hashes, sensitive configuration files, internal application logs, and documents shared across multiple company entities. This access can be used to gain complete control over the Dolibarr instance or to facilitate further attacks against the organization's broader infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all instances of Dolibarr to version 24.0.1 or later to apply the official vendor patch.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect exploitation attempts targeting the identified document endpoints.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for requests containing the 'hashp=shared' parameter string.\u003c/li\u003e\n\u003cli\u003eConduct an audit of accessed files and user logs for unauthorized document retrieval following any identified exploitation attempts.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-12T00:37:51Z","date_published":"2026-09-11T17:14:22Z","id":"https://feed.craftedsignal.io/briefs/2026-09-dolibarr-auth-bypass/","summary":"An unauthenticated authorization bypass vulnerability in Dolibarr allows remote attackers to access arbitrary sensitive files via the document storage endpoints.","title":"Authorization Bypass in Dolibarr Document Storage","url":"https://feed.craftedsignal.io/briefs/2026-09-dolibarr-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Dolibarr (23.0.4 - 24.0.0)","version":"https://jsonfeed.org/version/1.1"}