漏洞描述
Dolibarr ERP/CRM versions 23.0.4 through 24.0.0 contain an authorization bypass vulnerability in document.php and viewimage.php. The public share-link feature forces NOLOGIN when hashp is present, but the value 'shared' skips token resolution while the override still fires for any non-empty hashp value. This bypass allows unauthenticated remote attackers to read arbitrary files from all Dolibarr managed directories including logs, SQL database backups, invoices, contracts, user vcards, and custom module sources.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
github.comhttps://github.com/Faceless0x7/CVE-2026-89013↗github.comhttps://github.com/Dolibarr/dolibarr/commit/cd05688dbed8a4af6eef32faf4fc1e823a37bce9↗github.comhttps://github.com/Dolibarr/dolibarr/commit/a8bc4a63e1b6356884abcd83c4a38954d9649b0b↗github.comhttps://github.com/Dolibarr/dolibarr/commit/3bd8aa8b909e596d7dab4388d0466ec24e6ad191↗github.comhttps://github.com/Dolibarr/dolibarr/releases/tag/24.0.1↗www.vulncheck.comhttps://www.vulncheck.com/advisories/dolibarr-authorization-bypass-via-hashp-parameter-in-document-php↗previdian.comhttps://previdian.com/CVE-2026-89013↗nvd.nist.govhttp://nvd.nist.gov/vuln/detail/CVE-2026-89013↗