{"id":"CVE-2026-71507","title":"Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account write routes that allows authenticated attackers with third-party creation rights to create, replace, or delete bank a…","summary":"Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account write routes that allows authenticated attackers with third-party creation rights to create, replace, or delete bank a…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","cwe":["CWE-639"],"published":"2026-08-24","updated":"2026-09-08","sourceUpdated":"2026-09-08T20:23:49.880","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-71507","references":[{"url":"https://codeant.ai/security-research/cve-2026-71507-dolibarr-bola-lets-attackers-redirect-supplier-payments","label":"disclosure@vulncheck.com"},{"url":"https://github.com/Dolibarr/dolibarr/commit/c100564d059e19c711317c734d302a90b11e2e8b","label":"disclosure@vulncheck.com"},{"url":"https://github.com/Dolibarr/dolibarr/releases/tag/24.0.0","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/dolibarr-rest-api-broken-object-level-authorization-via-bank-account-routes","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"epss":0.0022,"epssPercentile":0.12835,"ingestedAt":"2026-09-08T21:11:12.284Z","slug":"CVE-2026-71507","body":"## Overview\n\nDolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account write routes that allows authenticated attackers with third-party creation rights to create, replace, or delete bank account details of any company without requiring read access to that company. Attackers can inject attacker-controlled IBANs as creditor accounts, which are then written into regenerated SEPA credit-transfer files, redirecting outgoing payments to attacker-controlled accounts.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}