CVE-2026-7689 Details
Description
A security flaw has been discovered in Dolibarr ERP CRM up to 23.0.2. This vulnerability affects the function dol_verifyHash in the library htdocs/core/lib/security.lib.php of the component Online Signature Module. The manipulation results in improper verification of cryptographic signature. The attack may be performed from remote. Attacks of this nature are highly complex. It is stated that the exploitability is difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
An authentication bypass vulnerability has been identified in Dolibarr ERP CRM versions prior to 23.0.2. The issue resides in the Online Signature Module, specifically within the 'dol_verifyHash' function of 'htdocs/core/lib/security.lib.php'. This vulnerability allows remote attackers to improperly verify cryptographic signatures, enabling them to forge digital signatures on documents such as proposals and contracts. The vulnerability is exploitable under certain conditions, including an empty or misconfigured security token and the use of 'password_hash' as the main security hash algorithm.
Users are advised to ensure that the 'PROPOSAL_ONLINE_SIGNATURE_SECURITY_TOKEN' is properly configured and not empty. Additionally, consider reviewing the implementation of the 'dol_verifyHash' function to prevent bypassing signature validations.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 3, 2026CISA-ADP
Assessed May 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/Shaon-Xis/d6ae069fc54f006457b68a91d5a8e158 | [email protected] | ExploitTechnical Analysis |
| https://vuldb.com/submit/801794 | [email protected] | Permission Required |
| https://vuldb.com/vuln/360859 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/360859/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-345 | Insufficient Verification of Data Authenticity | [email protected] |
| CWE-347 | Improper Verification of Cryptographic Signature | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Dolibarr ERP CRM | <= 23.0.2 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 3, 2026 | New CVE Received | [email protected] |
Volerion