CVE-2026-23500Disclosure(dolibarr / dolibarr_erp\/crm)

LOWCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Patch dolibarr dolibarr_erp\/crm systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions prior to 23.0.0 , the ODT to PDF conversion process in odf.php concatenates the MAIN_ODT_AS_PDF configuration constant directly into a shell command passed to exec() without sanitization. An authenticated administrator can inject arbitrary OS commands via this constant using command separators, achieving remote code execution as the web server user when any ODT template is generated. This issue has been fixed in version 23.0.0.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dolibarr_erp\/crm

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 11 mentions across 7 observed days
  • Momentum state: rising

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 8 signals
  • Disclosure: 6 classified signals
  • General: 3 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-05-10)
  • 11 total mentions across 7 days

Affected systems

Vendors
Products
dolibarr_erp\/crm

Deep dive

Activity timeline11 mentions / 7d
01234Mentions · 2026-04-11: 1Mentions · 2026-04-17: 2Mentions · 2026-04-18: 1Mentions · 2026-04-19: 1Mentions · 2026-04-20: 1Mentions · 2026-04-21: 1Mentions · 2026-05-10: 4PoC Mentioned / Linked · 2026-04-17: 1PoC Mentioned / Linked · 2026-04-21: 1Patch / Workaround · 2026-04-20: 1Technical Details · 2026-04-17: 2Technical Details · 2026-04-19: 1Technical Details · 2026-04-20: 1Technical Details · 2026-04-21: 1Technical Details · 2026-05-10: 304-1104-1704-1804-1904-2004-2105-10
Signal classification4 categories
Disclosure
654.5%
General
327.3%
Patch
19.1%
PoC
19.1%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-04-111
General1
2026-04-172
Disclosure2
2026-04-181
Disclosure1
2026-04-191
Disclosure1
2026-04-201
Patch1
2026-04-211
PoC1
2026-05-104
Disclosure2General2
Full discourse11 posts
  • Hunter@HunterMapping
    PoC

    🚨Alert🚨 CVE-2026-23500(CVSS 9.4) : Critical Flaw Leaves Dolibarr ERP Open to RCE 🔥PoC :https://github.com/Dolibarr/dolibarr/security/advisories/GHSA-w5j3-8fcr-h87w 📊 56.8K Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22Dolibarr%22 👇Query HUNTER : http://product.name="Dolibarr" 📰Refer:https://securityonline.info/dolibarr-rce-vulnerability-cve-2026-23500-pdf-conversion/ #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    A GitHub‑linked PoC demonstrates a critical RCE in Dolibarr (CVE‑2026‑23500); the post lists technical details but shows no evidence of active exploitation or patch availability.

    016041113.5K
    26.0K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Dolibarr ERP faces a critical 9.4 CVSS RCE flaw (CVE-2026-23500) in its PDF conversion logic. Unsanitized commands allow full system takeover. Upgrade to 23.0! #Dolibarr #RCE #CyberSecurity #InfoSec #CVE202623500 #ERP #CRM #BugBounty https://securityonline.info/dolibarr-rce-vulnerability-cve-2026-23500-pdf-conversion/ https://t.co/JsEPJF17S8

    Post summary

    CVE-2026-23500 is a critical RCE flaw in Dolibarr's PDF conversion that allows full system takeover; upgrading to version 23.0 is the recommended mitigation.

    12083896
    12.5K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-23500-dolibarr-dolibarr-erp-crm #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The post links to a research page about CVE-2026-23500 but offers no specific information about the vulnerability, exploits, or mitigation.

    0000020
    189 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-23500 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory CRITICAL: CVE-2026-23500 (CVSS 9.1) — dolibarr dolibarr erp\/crm

    Post summary

    The advisory announces CVE-2026-23500 as a critical vulnerability (CVSS 9.1) affecting Dolibarr ERP/CRM, but provides no PoC, exploit, or patch information.

    0000034
    189 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVSS 9.1 CRITICAL · CVE-2026-23500 · 9.1 → 23.0.0 CRITICAL: CVE-2026-23500 (CVSS 9.1) — dolibarr dolibarr erp\/crm

    Post summary

    The entry merely lists CVE‑2026‑23500 with a CVSS score of 9.1 and a critical severity rating, offering no further technical context, exploit details, or mitigation information.

    0000032
    197 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-23500 (CVSS 9.1) — dolibarr dolibarr erp\/crm Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package.

    Post summary

    The text announces a critical vulnerability (CVE-2026-23500) in Dolibarr, providing its CVSS score of 9.1, without further details on exploitation or mitigation.

    0000037
    197 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `Dolibarr` affected by critical OS command injection (RCE) via `MAIN_ODT_AS_PDF` configuration. CVE-2026-23500 enables system compromise. Evaluate `Dolibarr` installations. #Dolibarr #RCE #AppSec https://www.pulsepatch.io/posts/cve-2026-23500-dolibarr-os-command-injection

    Post summary

    The post announces CVE-2026-23500, a critical RCE in Dolibarr triggered by the MAIN_ODT_AS_PDF configuration, and urges administrators to evaluate affected installations.

    0000079
    12 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23500 Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions prior to 23.0.0 , the ODT to PDF conversion… https://www.cve.org/CVERecord?id=CVE-2026-23500

    Post summary

    The text announces CVE‑2026‑23500 for Dolibarr, noting affected versions and a preliminary vulnerability area, but provides no PoC, exploit, patch, or proof of exploitation.

    00000157
    57.2K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Dolibarr ERP/CRM, #OS Command Injection, #CVE-2026-23500 (Critical) https://dailycve.com/dolibarr-erp-crm-os-command-injection-cve-2026-23500-critical/

    Post summary

    The tweet alerts about a critical OS Command Injection flaw in Dolibarr ERP/CRM (CVE-2026-23500) without providing exploit or patch details.

    0000047
    181 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-23500: Dolibarr: OS Command Injection (... Admin-level RCE in Dolibarr via unsanitized MAIN_ODT_AS_PDF config injection into exec() - classic shell command concat... https://zerodaysignal.com/vulnerability/CVE-2026-23500 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces a new OS Command Injection CVE in Dolibarr, including a link for more details and some technical specifics, but does not provide a PoC, exploit code, or patch information.

    0000067
    218 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-23500 CVE-2026-23500 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-23500

    Post summary

    The text merely references CVE-2026-23500 and includes a link to its Vulmon entry but provides no other details or context.

    0000045
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdolibarrdolibarr_erp\/crm---

Explore more