CVE-2026-78160 | Dolibarr ERP up to 18.0.10/22.0.5/23.0.3 User Notes /user/note.php ID authorization (Issue 39063)

SecurityVulns

A vulnerability was found in Dolibarr ERP up to 18.0.10/22.0.5/23.0.3. It has been rated as critical. This issue affects some unknown processing of the file /user/note.php of the component User Notes Handler. The manipulation of the argument ID leads to authorization bypass.

This vulnerability is documented as CVE-2026-78160. The attack can be initiated remotely. Additionally, an exploit exists.

Upgrading the affected component is advised.VulDB Recent EntriesRead More