CVE-2026-19930: LDAP Injection in Dolibarr
A security flaw has been discovered in Dolibarr up to 23.0.3. Affected is an unknown function of the file htdocs/user/card.php of the component User Cloning. The manipulation of the argument ID results in ldap injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The patch is identified as 798e65356ede03c2812ab1a728f23fae34de5592. It is advisable to implement a patch to correct this issue.
AI Analysis
Technical Summary
This vulnerability in Dolibarr up to version 23.0.3 involves LDAP injection via the manipulation of the ID argument in an unknown function in htdocs/user/card.php, part of the User Cloning component. The flaw allows remote attackers to inject LDAP queries, potentially leading to unauthorized LDAP operations. A patch commit (798e65356ede03c2812ab1a728f23fae34de5592) has been identified, but no official vendor advisory or remediation level is documented. The CVSS 4.0 score is 5.3 (medium), reflecting network attack vector, low complexity, no privileges required, no user interaction, and low to limited impact on confidentiality, integrity, and availability.
Potential Impact
The LDAP injection vulnerability could allow remote attackers to manipulate LDAP queries, potentially leading to unauthorized access or information disclosure related to LDAP directory data. The impact is rated medium based on CVSS 4.0 scoring, indicating limited but non-negligible risk.
Mitigation Recommendations
A patch commit has been identified (798e65356ede03c2812ab1a728f23fae34de5592) to address this issue. It is advisable to apply this patch to affected Dolibarr versions 23.0.0 through 23.0.3. No official vendor advisory or remediation level is currently available, so users should monitor vendor channels for confirmation and updated guidance.
CVE-2026-19930: LDAP Injection in Dolibarr
Description
A security flaw has been discovered in Dolibarr up to 23.0.3. Affected is an unknown function of the file htdocs/user/card.php of the component User Cloning. The manipulation of the argument ID results in ldap injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The patch is identified as 798e65356ede03c2812ab1a728f23fae34de5592. It is advisable to implement a patch to correct this issue.
CVSS v4.0
Score 5.3medium
Affected software
pkg:github/dolibarr/dolibarrcpe:2.3:a:dolibarr:dolibarr:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in Dolibarr up to version 23.0.3 involves LDAP injection via the manipulation of the ID argument in an unknown function in htdocs/user/card.php, part of the User Cloning component. The flaw allows remote attackers to inject LDAP queries, potentially leading to unauthorized LDAP operations. A patch commit (798e65356ede03c2812ab1a728f23fae34de5592) has been identified, but no official vendor advisory or remediation level is documented. The CVSS 4.0 score is 5.3 (medium), reflecting network attack vector, low complexity, no privileges required, no user interaction, and low to limited impact on confidentiality, integrity, and availability.
Potential Impact
The LDAP injection vulnerability could allow remote attackers to manipulate LDAP queries, potentially leading to unauthorized access or information disclosure related to LDAP directory data. The impact is rated medium based on CVSS 4.0 scoring, indicating limited but non-negligible risk.
Mitigation Recommendations
A patch commit has been identified (798e65356ede03c2812ab1a728f23fae34de5592) to address this issue. It is advisable to apply this patch to affected Dolibarr versions 23.0.0 through 23.0.3. No official vendor advisory or remediation level is currently available, so users should monitor vendor channels for confirmation and updated guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-08-15T06:00:50.348Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a813177bf8831d53961f59b
Added to database: 08/16/2026, 03:41:43 UTC
Last enriched: 08/23/2026, 13:22:08 UTC
Last updated: 09/06/2026, 10:52:07 UTC
Views: 48
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.