Skip to content
TrustList
News

Dolibarr ERP file-read flaw CVE-2026-89013 is reported exploited: update to 24.0.1

Editorial

By TrustList Editorial

A Dolibarr flaw, CVE-2026-89013, lets unauthenticated attackers read arbitrary files, including business documents and database backups, in versions 23.0.4 to before 24.0.1. Italy’s cyber agency reports it exploited. Update to 24.0.1.

About Dolibarr ERP file-read flaw CVE-2026-89013 is reported exploited: update to 24.0.1

Dolibarr ERP file-read flaw CVE-2026-89013 is reported exploited: update to 24.0.1

30 September 2026 — Dolibarr is an open-source ERP and CRM used by many small businesses, associations and the IT firms that host it for them. It has an authorisation-bypass vulnerability, CVE-2026-89013, which lets an unauthenticated attacker read arbitrary files. The flaw was disclosed and fixed in Dolibarr 24.0.1 in September. On 30 September 2026, Italy's national cyber agency (ACN / CSIRT Italia) reported that it is being exploited and that proof-of-concept code is public.

What the flaw does

According to the GitHub security advisory (GHSA-fm6p-42mr-x6jm, published 11 September 2026):

  • Affected versions: Dolibarr 23.0.4 and later, before 24.0.1.
  • The bug: attackers can send a request to the document storage endpoints (htdocs/document.php and htdocs/viewimage.php) with the hashp parameter set to "shared". This skips token validation while still satisfying the authorisation check.
  • What can be read: application logs, uploaded business documents, database backups containing password hashes, and files belonging to other entities in multi-company set-ups.

The advisory rates it high, with a CVSS score of 7.5. ACN gives a CVSS 4.0 score of 8.7.

Why it matters

An ERP holds invoices, contracts, customer and supplier records and staff data. Backups with password hashes can lead to account takeover, and multi-company installations, often run by hosting providers for several clients, can leak one client's files to an attacker probing another's. The attack needs no login, so any Dolibarr reachable from the internet is exposed.

Not yet independently verified. The report that the flaw is being exploited comes from Italy’s national cyber agency alone; the Dolibarr project’s own pages read so far describe the fix but do not mention exploitation. We will update this when it can be confirmed, and remove this note.

What to do

  • Update every Dolibarr installation from 23.0.4 onwards to 24.0.1 or later.
  • If it cannot be updated at once, block external access to document.php and viewimage.php, or put the instance behind a VPN.
  • Check web-server logs for requests to those endpoints carrying hashp=shared.
  • If you find any, assume documents and backups were read: rotate user passwords and any credentials stored in documents.
  • Hosting providers running Dolibarr for clients should patch every tenant and tell affected clients.

Sources

Categories & features