CVE-2026-58376Disclosure

LOWCVSS 7.2 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Dolibarr through 23.0.3, fixed in commit 14db36e, contains a sql injection vulnerability that allows authenticated API users to exfiltrate arbitrary database contents by supplying malicious values to the sqlfilters query parameter in the setup dictionary and multicurrencies REST API endpoints. The affected endpoints in api_setup.class.php and api_multicurrencies.class.php validate sqlfilters only for balanced parentheses and rewrite matched triplets, allowing text placed outside the expected shape such as an appended UNION SELECT to be concatenated into the SQL WHERE clause unmodified, enabling retrieval of sensitive data including password hashes and API keys.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-30: 2Patch / Workaround · 2026-06-30: 2Technical Details · 2026-06-30: 206-30
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-58376 Dolibarr through 23.0.3, fixed in commit 14db36e, contains a sql injection vulnerability that allows authenticated API users to exfiltrate arbitrary database contents… https://www.cve.org/CVERecord?id=CVE-2026-58376 ----- Traducción: CVE-2026-58376 Dol… http://infoflow.cloud`

    Post summary

    The post announces a SQL injection vulnerability in Dolibarr that lets authenticated API users extract database data and notes that it has been fixed in a recent commit.

    0000037
    89 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-58376 Dolibarr through 23.0.3, fixed in commit 14db36e, contains a sql injection vulnerability that allows authenticated API users to exfiltrate arbitrary database contents… https://www.cve.org/CVERecord?id=CVE-2026-58376

    Post summary

    The message announces a SQL injection vulnerability in Dolibarr 23.0.3, notes a specific patch commit, and provides technical details of the flaw.

    00000907
    57.7K followersView on X

Explore more