Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive denylist bypass vulnerability in the sqlfilters API query parameter that allows… (CVE-2026-89012)
Dolibarr version 24.0.0 contains a case-sensitive denylist bypass vulnerability in the sqlfilters API query parameter. This flaw allows authenticated attackers to bypass protections by using uppercase variants of denylist-protected field names. Exploiting this, attackers can recover protected database fields, including full password hashes for any user account, such as administrators.
AI Analysis
Technical Summary
Dolibarr 24.0.0 has a vulnerability (CVE-2026-89012) where the sqlfilters API query parameter uses a case-sensitive denylist to block certain database fields. However, the underlying database column resolution is case-insensitive, allowing attackers to bypass the denylist by supplying uppercase variants of protected field names. This bypass enables attackers with authentication to use prefix-matching predicates as a boolean oracle to extract sensitive data, including full password hashes for all user accounts, including administrators.
Potential Impact
An authenticated attacker can bypass the denylist protection in the sqlfilters API to access protected database fields. This includes the ability to extract full password hashes for any user account, potentially leading to credential compromise and unauthorized access to administrative accounts. The vulnerability impacts confidentiality but does not affect integrity or availability.
Mitigation Recommendations
A fix is available in Dolibarr version 24.0.1. Users should upgrade from version 24.0.0 to 24.0.1 to remediate this vulnerability. No additional mitigation guidance is provided or required beyond applying the official patch.
Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive denylist bypass vulnerability in the sqlfilters API query parameter that allows… (CVE-2026-89012)
Description
Dolibarr version 24.0.0 contains a case-sensitive denylist bypass vulnerability in the sqlfilters API query parameter. This flaw allows authenticated attackers to bypass protections by using uppercase variants of denylist-protected field names. Exploiting this, attackers can recover protected database fields, including full password hashes for any user account, such as administrators.
CVSS v3.1
Score 6.5medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Dolibarr 24.0.0 has a vulnerability (CVE-2026-89012) where the sqlfilters API query parameter uses a case-sensitive denylist to block certain database fields. However, the underlying database column resolution is case-insensitive, allowing attackers to bypass the denylist by supplying uppercase variants of protected field names. This bypass enables attackers with authentication to use prefix-matching predicates as a boolean oracle to extract sensitive data, including full password hashes for all user accounts, including administrators.
Potential Impact
An authenticated attacker can bypass the denylist protection in the sqlfilters API to access protected database fields. This includes the ability to extract full password hashes for any user account, potentially leading to credential compromise and unauthorized access to administrative accounts. The vulnerability impacts confidentiality but does not affect integrity or availability.
Mitigation Recommendations
A fix is available in Dolibarr version 24.0.1. Users should upgrade from version 24.0.0 to 24.0.1 to remediate this vulnerability. No additional mitigation guidance is provided or required beyond applying the official patch.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-vhvr-3m2v-rrfq
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-89012"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6aa47ebd55bf5e2cf58579c7
Added to database: 09/11/2026, 22:20:45 UTC
Last enriched: 09/11/2026, 22:31:53 UTC
Last updated: 09/11/2026, 23:11:20 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.