No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 27 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 24 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dolibarr
Dolibarr dolibarr |
|
| Vendors & Products |
Dolibarr
Dolibarr dolibarr |
Mon, 24 Aug 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers with only member-creation rights to reset the password of any user account, including the system administrator, without verifying password-change permissions. Attackers can supply an arbitrary user account identifier and new password in the request body to overwrite credentials and immediately lock out the legitimate account holder. | |
| Title | Dolibarr < 24.0.0 Members REST API Improper Authorization via Password Reset | |
| Weaknesses | CWE-862 CWE-915 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-29T11:47:36.048Z
Reserved: 2026-08-06T20:42:17.834Z
Link: CVE-2026-71504
Updated: 2026-08-27T14:02:54.828Z
Status : Deferred
Published: 2026-08-24T19:16:49.670
Modified: 2026-09-08T20:23:49.880
Link: CVE-2026-71504
No data.
OpenCVE Enrichment
Updated: 2026-08-24T20:45:03Z