vulns.co
/
GKData.io MCP

CodeAnt AI · 1 min read

Dolibarr portal accounts: credential writes need object authorization

Research on CVE-2026-71505 describes inconsistent authorization between reading and modifying company portal accounts. A role-level check did not establish authority over the particular company. In researcher-owned fixtures, the omission enabled account takeover, invoice access and disclosure of stored password verifiers.

Open the reference Research PaperReviewed 2026-10-03

How to use this reference

Apply actor-to-object checks consistently to every credential mutation. The linked maintainer patch adds resource checks to account creation, update and deletion; the CNA identifies versions before 24.0.0 as affected. Editorially, keep credential changes explicitly permissioned and sensitive verifiers out of responses.

Before reading

  • Basic authentication and access-control concepts
  • Familiarity with application trust boundaries

Context and limits

  • An authenticated principal with third-party creation rights is required. The researcher's demonstrated fixture also held read-companies rights, although the article identifies creation rights as sufficient for the vulnerable write.
  • Observed evidence comes from a local development build with fixture companies, not customer accounts. Disclosed password hashes were not shown cracked.
  • The researcher lists CVSS 8.1; the CNA gives CVSS v4 7.1. Scores are preserved as different source claims, not reconciled.
  • Article publication (August 23) and CNA publication (August 24, 2026) are distinct. Learning prerequisites are editorial.

Sources and provenance

  1. CVE-2026-71505: Dolibarr BOLA Enables Portal Account Takeover CodeAnt AI · reviewed 2026-10-03
  2. Dolibarr < 24.0.0 REST API Broken Object-Level Authorization via Third-Party Write Route VulnCheck · reviewed 2026-10-03
  3. Fix prevent edit by external users - reported by VulnCheck Dolibarr · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software