GHSA-mfxx-qcw7-5q5rMediumCVSS 4.3

Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the...

Published
August 30, 2026
Last Modified
August 30, 2026

🔗 CVE IDs covered (1)

📋 Description

Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the Users::getGroups REST API endpoint, allowing authenticated users to retrieve group memberships of other users. Attackers can call GET /users/{id}/groups with arbitrary user identifiers to access group names, entity associations, and private notes across tenant boundaries.

🔗 References (7)