---
id: CVE-2026-77923
title: Dolibarr 21.0.0 < 24.0.0 Authorization Bypass via clonetasks Mass Action
summary: >-
  Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability
  caused by an inverted boolean condition in the private-project membership
  check within the clonetasks mass action handler in
  htdocs/core/actions_massactions.inc…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cvssSource: cna
cwe:
  - CWE-863
vendor: Dolibarr
product: dolibarr
affected:
  - dolibarr >= 21.0.0 < 24.0.0
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-24T20:01:47.486619Z'
published: '2026-08-24'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:21:16.329Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-77923'
references:
  - url: 'https://github.com/Dolibarr/dolibarr/releases/tag/24.0.0'
    label: Dolibarr 24.0.0 Release Notes
  - url: >-
      https://github.com/Dolibarr/dolibarr/commit/1730aa56675b31cfede895fdae55b673d887fb8f
    label: Patch Commit
  - url: >-
      https://www.vulncheck.com/advisories/dolibarr-authorization-bypass-via-clonetasks-mass-action
tags:
  - cve.org
epss: 0.00362
epssPercentile: 0.27607
ingestedAt: '2026-10-01T15:48:17.844Z'
---

## Overview

Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability caused by an inverted boolean condition in the private-project membership check within the clonetasks mass action handler in htdocs/core/actions_massactions.inc.php. Authenticated users with project creation permission but without access to a target private project can exploit the flawed !in_array() check to clone tasks into unauthorized private projects.

## Affected

- `dolibarr >= 21.0.0 < 24.0.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
