{"id":"CVE-2026-107706","summary":"Dolibarr before 24.0.2 Incorrect Authorization via updateextrafield.php","details":"Dolibarr ERP CRM before 24.0.2 contains an incorrect authorization vulnerability in htdocs/core/ajax/updateextrafield.php that checks only read permission before writing extrafield values. Authenticated users with read-only access can POST objectType, objectId, field and value parameters to persistently modify extrafields on viewable third parties, products, members, projects or contacts.","modified":"2026-10-10T02:47:27.829753025Z","published":"2026-10-08T19:51:13.651Z","database_specific":{"cwe_ids":["CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107706.json","cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107706.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107706"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/dolibarr-before-24.0.2-incorrect-authorization-via-updateextrafield-php"},{"type":"FIX","url":"https://github.com/Dolibarr/dolibarr/commit/3420d17b199059ac22fca8b59f23cb8962fc8ef8"},{"type":"PACKAGE","url":"https://github.com/Dolibarr/dolibarr"},{"type":"ARTICLE","url":"https://github.com/Dolibarr/dolibarr/blob/24.0.1/htdocs/core/ajax/updateextrafield.php#L80"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dolibarr/dolibarr","events":[{"introduced":"0"},{"fixed":"7e927764767343334aaa067ca5ec054cfea0a26b"},{"fixed":"3420d17b199059ac22fca8b59f23cb8962fc8ef8"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"24.0.2"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["24.0.1","24.0.0","lne_audit_init_20260601","14.0.0","14.0.1","6.0.0-beta","5.0.0-beta","4.0.0-rc","3.8.0-beta","3.7.1","3.7.0","3.6.2","3.6.1","3.6.0","3.6.0-beta","3.6.beta1_20140514","3.6.0-alpha","3.5.beta1_20131120","3.5.beta1_20131106","3.4.beta1_20130502","3.4.beta1_20130429","3.3.beta1_20121221"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107706.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}