{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/dolibarr-24.0.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-71504"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Dolibarr (24.0.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","rest-api","privilege-escalation","cve-2026-71504"],"_cs_type":"advisory","_cs_vendors":["Dolibarr"],"content_html":"\u003cp\u003eDolibarr versions prior to 24.0.0 are vulnerable to an improper authorization flaw (CVE-2026-71504) within the Members REST API. This vulnerability stems from a mass assignment issue that allows attackers possessing standard member-creation privileges to modify sensitive user account attributes. Specifically, an authenticated attacker can submit a crafted request to the API containing an arbitrary user identifier and a new password. The application fails to verify if the requester possesses the necessary permissions to change passwords, allowing the attacker to overwrite the credentials of any account, including the system administrator. This flaw facilitates full account takeover and enables the attacker to lock out legitimate users, presenting a significant risk to organizational identity management and data integrity.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker obtains valid credentials for a standard user account with at least member-creation privileges in the Dolibarr instance.\u003c/li\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify the endpoint for the Members REST API.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP POST request targeting the Members API endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker inserts an arbitrary 'user_id' and the desired 'password' into the request body, leveraging mass assignment properties.\u003c/li\u003e\n\u003cli\u003eThe Dolibarr server processes the request without enforcing authorization checks for password modification.\u003c/li\u003e\n\u003cli\u003eThe backend updates the target user's credentials in the database to the attacker-supplied password.\u003c/li\u003e\n\u003cli\u003eAttacker logs into the target account (including administrative accounts) using the updated credentials.\u003c/li\u003e\n\u003cli\u003eAttacker gains full access to the victim's resources or performs administrative actions.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-71504 results in unauthorized account takeover, including administrative accounts. This leads to complete compromise of the Dolibarr instance, potential exfiltration of sensitive member or organizational data, and denial of service for legitimate users who are locked out of their accounts. The vulnerability affects all Dolibarr installations running versions prior to 24.0.0.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate all Dolibarr instances to version 24.0.0 or later immediately.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious POST requests to the Members REST API, specifically looking for requests that include unexpected password change parameters.\u003c/li\u003e\n\u003cli\u003eAudit logs for unauthorized password resets occurring through the API for administrative accounts.\u003c/li\u003e\n\u003cli\u003eRestrict access to the Members REST API to only those service accounts or users strictly requiring member-creation privileges.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-24T20:06:34Z","date_published":"2026-08-24T20:06:34Z","id":"https://feed.craftedsignal.io/briefs/2026-08-dolibarr-api-auth/","summary":"An improper authorization vulnerability (CVE-2026-71504) in Dolibarr prior to version 24.0.0 allows authenticated users to overwrite the credentials of any account via the Members REST API.","title":"Dolibarr Members REST API Improper Authorization Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-08-dolibarr-api-auth/"}],"language":"en","title":"CraftedSignal Threat Feed - Dolibarr (24.0.0)","version":"https://jsonfeed.org/version/1.1"}