CVE-2026-81730 | Dolibarr up to 23.0.4 emailcollector emailcollector.lib.php saveAttachment filename path traversal
A vulnerability was found in Dolibarr up to 23.0.4. It has been rated as critical. This issue affects the function saveAttachment of the file htdocs/emailcollector/lib/emailcollector.lib.php of the component emailcollector. The manipulation of the argument filename leads to path traversal.
This vulnerability is traded as CVE-2026-81730. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.VulDB Recent EntriesRead More