CVE-2026-85401 | Dolibarr up to 21.0.4/22.0.5/23.0.3 Legacy File Manager config.inc.php access control (Issue 38963)
A vulnerability was found in Dolibarr up to 21.0.4/22.0.5/23.0.3 and classified as critical. Affected by this issue is some unknown functionality of the file htdocs/core/filemanagerdol/connectors/php/config.inc.php of the component Legacy File Manager. Executing a manipulation can lead to improper access controls.
This vulnerability is tracked as CVE-2026-85401. The attack can be launched remotely. Moreover, an exploit is present.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More