CVE-2026-85401 Details
Description
A weakness has been identified in Dolibarr up to 21.0.4/22.0.5/23.0.3. Affected by this issue is some unknown functionality of the file htdocs/core/filemanagerdol/connectors/php/config.inc.php of the component Legacy File Manager. Executing a manipulation can lead to improper access controls. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 23.0.4 can resolve this issue. This patch is called ef6631e9bd5ec4b8cec0e88f1796d3d10dad02ec. It is suggested to upgrade the affected component.
A broken access control vulnerability has been identified in Dolibarr versions prior to 21.0.4, 22.0.5, and 23.0.3. The issue resides in the legacy file manager component, specifically within the file 'htdocs/core/filemanagerdol/connectors/php/config.inc.php'. This vulnerability allows authenticated users, even those with no permissions, to access the file manager connector, browse the media directory, and upload files. The uploaded files could potentially be executed as PHP scripts, leading to remote code execution. This issue can be exploited remotely, and a public exploit is available.
Upgrading to Dolibarr version 23.0.4 addresses this vulnerability. Users can follow the upgrade instructions available on the Dolibarr wiki.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 4, 2026CISA-ADP
Assessed Sep 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Dolibarr/dolibarr/ | [email protected] | Vendor |
| https://github.com/Dolibarr/dolibarr/commit/ef6631e9bd5ec4b8cec0e88f1796d3d10dad02ec | [email protected] | Source CodeVendor |
| https://github.com/Dolibarr/dolibarr/issues/38963 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/Dolibarr/dolibarr/pull/39731 | [email protected] | Issue TrackingVendor |
| https://github.com/Dolibarr/dolibarr/releases/tag/23.0.4 | [email protected] | Release NotesVendor |
| https://vuldb.com/cve/CVE-2026-85401 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/894869 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/398543 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/398543/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Dolibarr | <= 21.0.4 (semver) <= 22.0.5 (semver) <= 23.0.3 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 4, 2026 | CVE Modified | CISA-ADP |
| Sep 4, 2026 | New CVE Received | [email protected] |
Volerion