logo

Critical 9.4 CVSS Flaw Leaves Dolibarr ERP Open to RCE

ID: 42afe005-c1b7-57d1-b638-2b6265784eef

STIX ID: report--42afe005-c1b7-57d1-b638-2b6265784eef

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-20

Date Updated: 2026-04-23

Author: Ddos

...
...

Dolibarr ERP & CRM contains a critical RCE (CVE-2026-23500, CVSS 9.4) in the ODT-to-PDF conversion logic where the MAIN_ODT_AS_PDF configuration is not properly validated, allowing command injection by an authenticated administrator; versions up to and including 22.0.4 are affected and administrators are advised to upgrade to 23.0 which contains the patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.