CVE-2026-107706 | Dolibarr up to 24.0.1 Ajax Extrafield Update updateextrafield.php objectType/objectId/field/value improper authorization
A vulnerability classified as problematic has been found in Dolibarr up to 24.0.1. The affected element is an unknown function of the file htdocs/core/ajax/updateextrafield.php of the component Ajax Extrafield Update. Performing a manipulation of the argument objectType/objectId/field/value results in improper authorization.
This vulnerability is known as CVE-2026-107706. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More