{"id":"CVE-2026-107706","title":"Dolibarr ERP CRM before 24.0.2 contains an incorrect authorization vulnerability in htdocs/core/ajax/updateextrafield.php that checks only read permission before writing extrafield values","summary":"Dolibarr ERP CRM before 24.0.2 contains an incorrect authorization vulnerability in htdocs/core/ajax/updateextrafield.php that checks only read permission before writing extrafield values. Authenticated users with read-only access can PO…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-863"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:17:52.097","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107706","references":[{"url":"https://github.com/Dolibarr/dolibarr","label":"disclosure@vulncheck.com"},{"url":"https://github.com/Dolibarr/dolibarr/blob/24.0.1/htdocs/core/ajax/updateextrafield.php#L80","label":"disclosure@vulncheck.com"},{"url":"https://github.com/Dolibarr/dolibarr/commit/3420d17b199059ac22fca8b59f23cb8962fc8ef8","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/dolibarr-before-24.0.2-incorrect-authorization-via-updateextrafield-php","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"ingestedAt":"2026-10-08T21:07:56.436Z","slug":"CVE-2026-107706","body":"## Overview\n\nDolibarr ERP CRM before 24.0.2 contains an incorrect authorization vulnerability in htdocs/core/ajax/updateextrafield.php that checks only read permission before writing extrafield values. Authenticated users with read-only access can POST objectType, objectId, field and value parameters to persistently modify extrafields on viewable third parties, products, members, projects or contacts.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}