CVE-2026-22666PoC(dolibarr / dolibarr_erp\/crm)

MEDIUMCVSS 8.6 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch dolibarr dolibarr_erp\/crm systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Dolibarr ERP/CRM versions prior to 23.0.2 contain an authenticated remote code execution vulnerability in the dol_eval_standard() function that fails to apply forbidden string checks in whitelist mode and does not detect PHP dynamic callable syntax. Attackers with administrator privileges can inject malicious payloads through computed extrafields or other evaluation paths using PHP dynamic callable syntax to bypass validation and achieve arbitrary command execution via eval().

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-95CWE-94

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dolibarr_erp\/crm

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-04-13); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
dolibarr_erp\/crm

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-04-13: 4Mentions · 2026-04-19: 1Mentions · 2026-04-21: 1PoC Mentioned / Linked · 2026-04-13: 4Exploit Tool / Code · 2026-04-13: 2Patch / Workaround · 2026-04-21: 1Technical Details · 2026-04-13: 4Technical Details · 2026-04-19: 1Technical Details · 2026-04-21: 104-1304-1904-21
Signal classification3 categories
PoC
466.7%
Disclosure
116.7%
Patch
116.7%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-134
PoC4
2026-04-191
Disclosure1
2026-04-211
Patch1
Full discourse6 posts
  • Nicolas Krassas@Dinosn
    PoC

    CVE-2026-22666: Dolibarr 23.0.0 dol_eval() whitelist bypass -> RCE (full write-up + PoC) https://jivasecurity.com/writeups/dolibarr-remote-code-execution-cve-2026-22666

    Post summary

    A detailed write‑up for CVE-2026-22666 is available, highlighting an RCE in Dolibarr 23.0.0 and including a PoC to demonstrate the exploit.

    1803372.0K
    157.5K followersView on X
  • /r/netsec@_r_netsec
    PoC

    CVE-2026-22666: Dolibarr 23.0.0 dol_eval() whitelist bypass -> RCE (full write-up + PoC) https://jivasecurity.com/writeups/dolibarr-remote-code-execution-cve-2026-22666

    Post summary

    The post announces CVE-2026-22666 in Dolibarr, detailing a whitelist bypass that results in remote code execution, and provides a full write‑up with a PoC linked.

    03040589
    33.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22666 Dolibarr ERP/CRM versions prior to 23.0.2 contain an authenticated remote code execution vulnerability in the dol_eval_standard() function that fails to apply forbidd… https://www.cve.org/CVERecord?id=CVE-2026-22666

    Post summary

    The statement announces CVE‑2026‑22666, describing an authenticated remote code execution flaw in Dolibarr ERP/CRM before v23.0.2 and linking to the CVE record.

    00010179
    57.2K followersView on X
  • PHP Sources@phpsources
    Patch

    Dolibarr 23.0.2 corrige une vulnérabilité critique RCE (CVE-2026-22666) et plusieurs bugs. Mise à jour de sécurité recommandée pour la version 23.0.x Downloader : https://phpsources.net/script/php/logiciels/2030-12_dolibarr-erp,23.0.2 #PHP #CodeGratuit #Developpement #WebDev https://t.co/TzeWK3AquF

    Post summary

    Dolibarr 23.0.2 has been released with a security update that fixes the critical RCE CVE‑2026‑22666; the update is recommended, with a download link provided.

    0000066
    350 followersView on X
  • Vivek | Cybersecurity@VivekIntel
    PoC

    🚨 Dolibarr ERP RCE (CVE-2026-22666) Broken whitelist + eval() → full command execution Lesson: eval is a loaded gun, not a feature https://jivasecurity.com/writeups/dolibarr-remote-code-execution-cve-2026-22666

    Post summary

    A Discord‑style post announces a RCE in Dolibarr (CVE‑2026‑22666) with technical details and a link to a writeup that likely includes a PoC; no active exploitation or patch info is provided.

    00000150
    5.6K followersView on X
  • Security Harvester@secharvesterx
    PoC

    CVE-2026-22666: Dolibarr 23.0.0 dol_eval() whitelist bypass -> RCE (full write-up + PoC) https://jivasecurity.com/writeups/dolibarr-remote-code-execution-cve-2026-22666 https://t.co/32iba6zxDT

    Post summary

    The tweet announces a full write‑up and PoC for CVE‑2026‑22666, demonstrating an RCE through a whitelist bypass in Dolibarr 23.0.0.

    00000109
    944 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdolibarrdolibarr_erp\/crm---

Explore more