How to use this reference
Apply actor-to-object checks consistently to every credential mutation. The linked maintainer patch adds resource checks to account creation, update and deletion; the CNA identifies versions before 24.0.0 as affected. Editorially, keep credential changes explicitly permissioned and sensitive verifiers out of responses.
Before reading
- Basic authentication and access-control concepts
- Familiarity with application trust boundaries
Context and limits
- An authenticated principal with third-party creation rights is required. The researcher's demonstrated fixture also held read-companies rights, although the article identifies creation rights as sufficient for the vulnerable write.
- Observed evidence comes from a local development build with fixture companies, not customer accounts. Disclosed password hashes were not shown cracked.
- The researcher lists CVSS 8.1; the CNA gives CVSS v4 7.1. Scores are preserved as different source claims, not reconciled.
- Article publication (August 23) and CNA publication (August 24, 2026) are distinct. Learning prerequisites are editorial.
Sources and provenance
- CVE-2026-71505: Dolibarr BOLA Enables Portal Account Takeover CodeAnt AI · reviewed 2026-10-03
- Dolibarr < 24.0.0 REST API Broken Object-Level Authorization via Third-Party Write Route VulnCheck · reviewed 2026-10-03
- Fix prevent edit by external users - reported by VulnCheck Dolibarr · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.