CVE-2026-89012
PoC largeCase-Sensitive Denylist Bypass in Dolibarr 24.0.0 Leaks Admin Password Hashes
Dolibarr 24.0.0 before 24.0.1 is affected by a case-sensitivity flaw (CWE-178) in the sqlfilters parameter of its API: the denylist that hides protected database fields checks field names case-sensitively, while database column resolution is case-insensitive. An authenticated API user can supply uppercase variants of denylisted field names inside prefix-matching predicates, turning the query responses into a boolean oracle that leaks hidden fields. By repeatedly probing, the attacker can recover full password hashes for any user account, including administrator accounts. All deployments running Dolibarr 24.0.0 (or any affected 24.0.x release before 24.0.1) with the API exposed to authenticated users are affected. No public proof-of-concept is known, the issue is not in CISA's KEV catalog, and there are no confirmed reports of exploitation in the wild.
What to do: Upgrade Dolibarr to 24.0.1 or later. Until patched, restrict the REST API to trusted authenticated users and consider disabling or filtering use of the sqlfilters parameter; because the flaw can expose password hashes, ensure strong password hashing and be prepared to rotate credentials if API access was shared with untrusted parties.
| Dolibarr ERP/CRM | 24.0.0 before 24.0.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive denylist bypass vulnerability in the sqlfilters API query parameter that allows authenticated attackers to recover protected database fields by supplying uppercase variants of denylist-protected field names. Attackers can exploit the case-insensitive database column resolution against the case-sensitive denylist check in the core library to use prefix-matching predicates as a boolean oracle and extract full password hashes for any user account, including administrators.
- Weakness
- CWE-178
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.