Critical 9.4 CVSS Flaw Leaves Dolibarr ERP Open to RCE
ID: 42afe005-c1b7-57d1-b638-2b6265784eef
STIX ID: report--42afe005-c1b7-57d1-b638-2b6265784eef
Feed Name: securityonline.info
Threat Score
Dolibarr ERP & CRM contains a critical RCE (CVE-2026-23500, CVSS 9.4) in the ODT-to-PDF conversion logic where the MAIN_ODT_AS_PDF configuration is not properly validated, allowing command injection by an authenticated administrator; versions up to and including 22.0.4 are affected and administrators are advised to upgrade to 23.0 which contains the patch.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
