Dolibarr ERP file-read flaw CVE-2026-89013 is reported exploited: update to 24.0.1
EditorialBy TrustList Editorial
A Dolibarr flaw, CVE-2026-89013, lets unauthenticated attackers read arbitrary files, including business documents and database backups, in versions 23.0.4 to before 24.0.1. Italy’s cyber agency reports it exploited. Update to 24.0.1.
- France
- Cybersecurity
- ERP Software
- CRM Software
- +1 more
About Dolibarr ERP file-read flaw CVE-2026-89013 is reported exploited: update to 24.0.1
Dolibarr ERP file-read flaw CVE-2026-89013 is reported exploited: update to 24.0.1
30 September 2026 — Dolibarr is an open-source ERP and CRM used by many small businesses, associations and the IT firms that host it for them. It has an authorisation-bypass vulnerability, CVE-2026-89013, which lets an unauthenticated attacker read arbitrary files. The flaw was disclosed and fixed in Dolibarr 24.0.1 in September. On 30 September 2026, Italy's national cyber agency (ACN / CSIRT Italia) reported that it is being exploited and that proof-of-concept code is public.
What the flaw does
According to the GitHub security advisory (GHSA-fm6p-42mr-x6jm, published 11 September 2026):
- Affected versions: Dolibarr 23.0.4 and later, before 24.0.1.
- The bug: attackers can send a request to the document storage endpoints (htdocs/document.php and htdocs/viewimage.php) with the hashp parameter set to "shared". This skips token validation while still satisfying the authorisation check.
- What can be read: application logs, uploaded business documents, database backups containing password hashes, and files belonging to other entities in multi-company set-ups.
The advisory rates it high, with a CVSS score of 7.5. ACN gives a CVSS 4.0 score of 8.7.
Why it matters
An ERP holds invoices, contracts, customer and supplier records and staff data. Backups with password hashes can lead to account takeover, and multi-company installations, often run by hosting providers for several clients, can leak one client's files to an attacker probing another's. The attack needs no login, so any Dolibarr reachable from the internet is exposed.
Not yet independently verified. The report that the flaw is being exploited comes from Italy’s national cyber agency alone; the Dolibarr project’s own pages read so far describe the fix but do not mention exploitation. We will update this when it can be confirmed, and remove this note.
What to do
- Update every Dolibarr installation from 23.0.4 onwards to 24.0.1 or later.
- If it cannot be updated at once, block external access to document.php and viewimage.php, or put the instance behind a VPN.
- Check web-server logs for requests to those endpoints carrying hashp=shared.
- If you find any, assume documents and backups were read: rotate user passwords and any credentials stored in documents.
- Hosting providers running Dolibarr for clients should patch every tenant and tell affected clients.
Sources
- GitHub Security Advisory GHSA-fm6p-42mr-x6jm: Dolibarr authorization bypass (CVE-2026-89013) — 11 September 2026
- Dolibarr release 24.0.1 — 11 September 2026
- ACN / CSIRT Italia: Dolibarr, rilevato sfruttamento in rete della CVE-2026-89013 — 30 September 2026
Categories & features
- France
- Cybersecurity
- ERP Software
- CRM Software
- Patch Management
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More FranceThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.