{"id":"CVE-2026-77923","title":"Dolibarr 21.0.0 < 24.0.0 Authorization Bypass via clonetasks Mass Action","summary":"Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability caused by an inverted boolean condition in the private-project membership check within the clonetasks mass action handler in htdocs/core/actions_massactions.inc…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","cvssSource":"cna","cwe":["CWE-863"],"vendor":"Dolibarr","product":"dolibarr","affected":["dolibarr >= 21.0.0 < 24.0.0"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-08-24T20:01:47.486619Z"},"published":"2026-08-24","updated":"2026-10-01","sourceUpdated":"2026-10-01T15:21:16.329Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-77923","references":[{"url":"https://github.com/Dolibarr/dolibarr/releases/tag/24.0.0","label":"Dolibarr 24.0.0 Release Notes"},{"url":"https://github.com/Dolibarr/dolibarr/commit/1730aa56675b31cfede895fdae55b673d887fb8f","label":"Patch Commit"},{"url":"https://www.vulncheck.com/advisories/dolibarr-authorization-bypass-via-clonetasks-mass-action"}],"tags":["cve.org"],"epss":0.00362,"epssPercentile":0.27607,"ingestedAt":"2026-10-01T15:48:17.844Z","slug":"CVE-2026-77923","body":"## Overview\n\nDolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability caused by an inverted boolean condition in the private-project membership check within the clonetasks mass action handler in htdocs/core/actions_massactions.inc.php. Authenticated users with project creation permission but without access to a target private project can exploit the flawed !in_array() check to clone tasks into unauthorized private projects.\n\n## Affected\n\n- `dolibarr >= 21.0.0 < 24.0.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}