CVE-2026-19350: Missing Authorization in Dolibarr ERP
A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component TakePOS Module. Such manipulation leads to missing authorization. The attack may be performed from remote. The name of the patch is 8992ce8704da947b6abe7b65a6fe59aed736bb81. It is advisable to implement a patch to correct this issue.
AI Analysis
Technical Summary
This vulnerability affects Dolibarr ERP up to version 23.0.3 in the TakePOS module. The issue is a missing authorization check in the 'fail' function within htdocs/takepos/invoice.php, which can be exploited remotely to bypass intended access controls. The vulnerability has a CVSS 4.0 base score of 5.3, indicating medium severity. A patch commit (hash 8992ce8704da947b6abe7b65a6fe59aed736bb81) is referenced, but no official vendor advisory or detailed remediation instructions are available at this time.
Potential Impact
The missing authorization allows remote attackers to perform actions without proper permissions in the TakePOS module of Dolibarr ERP. This could lead to unauthorized operations related to invoicing within the ERP system. The impact is limited to the affected versions and the specific module.
Mitigation Recommendations
A patch commit has been identified for this vulnerability. It is advisable to apply the patch to Dolibarr ERP versions 23.0.0 through 23.0.3 to correct the missing authorization issue. Since no official vendor advisory or remediation level is provided, users should monitor Dolibarr's official channels for an official fix and apply updates promptly once available.
CVE-2026-19350: Missing Authorization in Dolibarr ERP
Description
A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component TakePOS Module. Such manipulation leads to missing authorization. The attack may be performed from remote. The name of the patch is 8992ce8704da947b6abe7b65a6fe59aed736bb81. It is advisable to implement a patch to correct this issue.
CVSS v4.0
Score 5.3medium
Affected software
Dolibarr
ERP
pkg:github/dolibarr/dolibarrcpe:2.3:a:dolibarr:erp:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability affects Dolibarr ERP up to version 23.0.3 in the TakePOS module. The issue is a missing authorization check in the 'fail' function within htdocs/takepos/invoice.php, which can be exploited remotely to bypass intended access controls. The vulnerability has a CVSS 4.0 base score of 5.3, indicating medium severity. A patch commit (hash 8992ce8704da947b6abe7b65a6fe59aed736bb81) is referenced, but no official vendor advisory or detailed remediation instructions are available at this time.
Potential Impact
The missing authorization allows remote attackers to perform actions without proper permissions in the TakePOS module of Dolibarr ERP. This could lead to unauthorized operations related to invoicing within the ERP system. The impact is limited to the affected versions and the specific module.
Mitigation Recommendations
A patch commit has been identified for this vulnerability. It is advisable to apply the patch to Dolibarr ERP versions 23.0.0 through 23.0.3 to correct the missing authorization issue. Since no official vendor advisory or remediation level is provided, users should monitor Dolibarr's official channels for an official fix and apply updates promptly once available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-08-08T16:27:24.385Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a785cedbf8831d53978db26
Added to database: 08/09/2026, 10:56:45 UTC
Last enriched: 08/16/2026, 15:07:35 UTC
Last updated: 09/23/2026, 13:47:42 UTC
Views: 67
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.